LWN.net Logo

libarchive: arbitrary code execution

Package(s):libarchive CVE #(s):CVE-2011-1777 CVE-2011-1778
Created:December 1, 2011 Updated:February 21, 2012
Description: From the Red Hat advisory:

Two heap-based buffer overflow flaws were discovered in libarchive. If a user were tricked into expanding a specially-crafted ISO 9660 CD-ROM image or tar archive with an application using libarchive, it could cause the application to crash or, potentially, execute arbitrary code with the privileges of the user running the application. (CVE-2011-1777, CVE-2011-1778)

Alerts:
Ubuntu USN-1310-1 2011-12-19
Mandriva MDVSA-2011:191 2011-12-18
Mandriva MDVSA-2011:190 2011-12-18
Scientific Linux SL-liba-20111201 2011-12-01
Oracle ELSA-2011-1507 2011-12-01
Red Hat RHSA-2011:1507-01 2011-12-01
Debian DSA-2413-1 2012-02-20

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds