PT-2017-9736 · Libarchive+3 · Libarchive+3
Doran Moppert
·
Published
2016-11-25
·
Updated
2024-06-15
·
CVE-2016-8688
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
libarchive version 3.2.1
Description
The issue is related to the mtree bidder in libarchive, which does not properly track line sizes when extending the read-ahead. This allows remote attackers to cause a denial of service, resulting in a crash, by providing a crafted file. The crash is triggered by an invalid read in either the
detect form or bid entry function in libarchive/archive read support format mtree.c.Recommendations
For libarchive version 3.2.1, consider restricting the use of the mtree bidder until a patch is available. As a temporary workaround, avoid using the
detect form or bid entry functions in libarchive/archive read support format mtree.c to minimize the risk of exploitation.Fix
DoS
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Suse
Ubuntu
Libarchive