libarchive: two vulnerabilities
| Package(s): | libarchive | CVE #(s): | CVE-2015-8915 CVE-2016-7166 | ||||||||||||||||||||||||||||||||||||
| Created: | September 12, 2016 | Updated: | September 14, 2016 | ||||||||||||||||||||||||||||||||||||
| Description: | From the Debian LTS advisory:
CVE-2015-8915: Paris Zoumpouloglou of Project Zero labs discovered a flaw in libarchive bsdtar. Using a crafted file bsdtar can perform an out-of-bounds memory read which will lead to a SEGFAULT. CVE-2016-7166: Alexander Cherepanov discovered a flaw in libarchive compression handling. Using a crafted gzip file, one can get libarchive to invoke an infinite chain of gzip compressors until all the memory has been exhausted or another resource limit kicks in. | ||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||
