|
|
Log in / Subscribe / Register

libarchive: two vulnerabilities

Package(s):libarchive CVE #(s):CVE-2015-8915 CVE-2016-7166
Created:September 12, 2016 Updated:September 14, 2016
Description: From the Debian LTS advisory:

CVE-2015-8915: Paris Zoumpouloglou of Project Zero labs discovered a flaw in libarchive bsdtar. Using a crafted file bsdtar can perform an out-of-bounds memory read which will lead to a SEGFAULT.

CVE-2016-7166: Alexander Cherepanov discovered a flaw in libarchive compression handling. Using a crafted gzip file, one can get libarchive to invoke an infinite chain of gzip compressors until all the memory has been exhausted or another resource limit kicks in.

Alerts:
Debian DSA-3677-1 libarchive 2016-09-25
CentOS CESA-2016:1844 libarchive 2016-09-16
CentOS CESA-2016:1850 libarchive 2016-09-15
Scientific Linux SLSA-2016:1850-1 libarchive 2016-09-12
Scientific Linux SLSA-2016:1844-1 libarchive 2016-09-12
Red Hat RHSA-2016:1850-01 libarchive 2016-09-12
Red Hat RHSA-2016:1844-01 libarchive 2016-09-12
Debian-LTS DLA-617-1 libarchive 2016-09-10
Gentoo 201701-03 libarchive 2017-01-01

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds