|
|
| |
|
| |
libarchive: arbitrary code execution
| Package(s): | libarchive |
CVE #(s): | CVE-2011-1777
CVE-2011-1778
|
| Created: | December 1, 2011 |
Updated: | February 21, 2012 |
| Description: |
From the Red Hat advisory:
Two heap-based buffer overflow flaws were discovered in libarchive. If a
user were tricked into expanding a specially-crafted ISO 9660 CD-ROM image
or tar archive with an application using libarchive, it could cause the
application to crash or, potentially, execute arbitrary code with the
privileges of the user running the application. (CVE-2011-1777,
CVE-2011-1778)
|
| Alerts: |
|
( Log in to post comments)
|
|
|