libarchive: file overwrite
| Package(s): | libarchive | CVE #(s): | CVE-2016-5418 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | September 13, 2016 | Updated: | October 17, 2016 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the Red Hat advisory:
A flaw was found in the way libarchive handled hardlink archive entries of non-zero size. Combined with flaws in libarchive's file system sandboxing, this issue could cause an application using libarchive to overwrite arbitrary files with arbitrary data from the archive. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
