ALT-PU-2016-1654-1
Package libarchive updated to version 3.2.1-alt1 for branch sisyphus in task 166450.
Closed vulnerabilities
BDU:2016-01145
Уязвимость библиотеки libarchive, позволяющая нарушителю выполнить произвольный код
BDU:2018-00005
Уязвимость библиотеки libarchive, существующая из-за ошибки управления ресурсами, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2015-8915
bsdcpio in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read and crash) via crafted cpio file.
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- 91298
- 91298
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://github.com/libarchive/libarchive/issues/503
- https://github.com/libarchive/libarchive/issues/503
- [debian-lts-announce] 20181129 [SECURITY] [DLA 1600-1] libarchive security update
- [debian-lts-announce] 20181129 [SECURITY] [DLA 1600-1] libarchive security update
- GLSA-201701-03
- GLSA-201701-03
Modified: 2024-11-21
CVE-2015-8916
bsdtar in libarchive before 3.2.0 returns a success code without filling the entry when the header is a "split file in multivolume RAR," which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted rar file.
- RHSA-2016:1844
- RHSA-2016:1844
- DSA-3657
- DSA-3657
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 91296
- 91296
- USN-3033-1
- USN-3033-1
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://github.com/libarchive/libarchive/issues/504
- https://github.com/libarchive/libarchive/issues/504
- GLSA-201701-03
- GLSA-201701-03
- https://security-tracker.debian.org/tracker/CVE-2015-8916
- https://security-tracker.debian.org/tracker/CVE-2015-8916
Modified: 2024-11-21
CVE-2015-8917
bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid character in the name of a cab file.
- RHSA-2016:1844
- RHSA-2016:1844
- DSA-3657
- DSA-3657
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 91303
- 91303
- USN-3033-1
- USN-3033-1
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://github.com/libarchive/libarchive/issues/505
- https://github.com/libarchive/libarchive/issues/505
- GLSA-201701-03
- GLSA-201701-03
- https://security-tracker.debian.org/tracker/CVE-2015-8917
- https://security-tracker.debian.org/tracker/CVE-2015-8917
Modified: 2024-11-21
CVE-2015-8918
The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted cab files, related to "overlapping memcpy."
- SUSE-SU-2016:1909
- SUSE-SU-2016:1909
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- 91300
- 91300
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://github.com/libarchive/libarchive/issues/506
- https://github.com/libarchive/libarchive/issues/506
- GLSA-201701-03
- GLSA-201701-03
Modified: 2024-11-21
CVE-2015-8919
The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap) via a crafted (1) lzh or (2) lha file.
- SUSE-SU-2016:1909
- SUSE-SU-2016:1909
- RHSA-2016:1844
- RHSA-2016:1844
- DSA-3657
- DSA-3657
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 91302
- 91302
- USN-3033-1
- USN-3033-1
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://github.com/libarchive/libarchive/issues/510
- https://github.com/libarchive/libarchive/issues/510
- GLSA-201701-03
- GLSA-201701-03
Modified: 2024-11-21
CVE-2015-8920
The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds stack read) via a crafted ar file.
- SUSE-SU-2016:1909
- SUSE-SU-2016:1909
- RHSA-2016:1844
- RHSA-2016:1844
- RHSA-2016:1850
- RHSA-2016:1850
- DSA-3657
- DSA-3657
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 91301
- 91301
- USN-3033-1
- USN-3033-1
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://github.com/libarchive/libarchive/issues/511
- https://github.com/libarchive/libarchive/issues/511
- GLSA-201701-03
- GLSA-201701-03
Modified: 2024-11-21
CVE-2015-8921
The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file.
- SUSE-SU-2016:1909
- SUSE-SU-2016:1909
- RHSA-2016:1844
- RHSA-2016:1844
- RHSA-2016:1850
- RHSA-2016:1850
- DSA-3657
- DSA-3657
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 91307
- 91307
- USN-3033-1
- USN-3033-1
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://github.com/libarchive/libarchive/issues/512
- https://github.com/libarchive/libarchive/issues/512
- GLSA-201701-03
- GLSA-201701-03
Modified: 2024-11-21
CVE-2015-8922
The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted 7z file, related to the _7z_folder struct.
- SUSE-SU-2016:1909
- SUSE-SU-2016:1909
- RHSA-2016:1844
- RHSA-2016:1844
- DSA-3657
- DSA-3657
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 91312
- 91312
- USN-3033-1
- USN-3033-1
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://github.com/libarchive/libarchive/issues/513
- https://github.com/libarchive/libarchive/issues/513
- GLSA-201701-03
- GLSA-201701-03
- https://www.suse.com/security/cve/CVE-2015-8922.html
- https://www.suse.com/security/cve/CVE-2015-8922.html
Modified: 2024-11-21
CVE-2015-8923
The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file.
- SUSE-SU-2016:1909
- SUSE-SU-2016:1909
- RHSA-2016:1844
- RHSA-2016:1844
- DSA-3657
- DSA-3657
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 91309
- 91309
- USN-3033-1
- USN-3033-1
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://github.com/libarchive/libarchive/issues/514
- https://github.com/libarchive/libarchive/issues/514
- GLSA-201701-03
- GLSA-201701-03
Modified: 2024-11-21
CVE-2015-8924
The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tar file.
- SUSE-SU-2016:1909
- SUSE-SU-2016:1909
- RHSA-2016:1844
- RHSA-2016:1844
- DSA-3657
- DSA-3657
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 91308
- 91308
- USN-3033-1
- USN-3033-1
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://github.com/libarchive/libarchive/issues/515
- https://github.com/libarchive/libarchive/issues/515
- GLSA-201701-03
- GLSA-201701-03
Modified: 2024-11-21
CVE-2015-8925
The readline function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read) via a crafted mtree file, related to newline parsing.
- SUSE-SU-2016:1909
- SUSE-SU-2016:1909
- RHSA-2016:1844
- RHSA-2016:1844
- DSA-3657
- DSA-3657
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 91306
- 91306
- USN-3033-1
- USN-3033-1
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://github.com/libarchive/libarchive/issues/516
- https://github.com/libarchive/libarchive/issues/516
- GLSA-201701-03
- GLSA-201701-03
Modified: 2024-11-21
CVE-2015-8926
The archive_read_format_rar_read_data function in archive_read_support_format_rar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted rar archive.
- SUSE-SU-2016:1909
- SUSE-SU-2016:1909
- RHSA-2016:1844
- RHSA-2016:1844
- DSA-3657
- DSA-3657
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 91304
- 91304
- USN-3033-1
- USN-3033-1
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://github.com/libarchive/libarchive/issues/518
- https://github.com/libarchive/libarchive/issues/518
- GLSA-201701-03
- GLSA-201701-03
Modified: 2024-11-21
CVE-2015-8927
The trad_enc_decrypt_update function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted zip file, related to reading the password.
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- 91329
- 91329
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://github.com/libarchive/libarchive/issues/523
- https://github.com/libarchive/libarchive/issues/523
- GLSA-201701-03
- GLSA-201701-03
Modified: 2024-11-21
CVE-2015-8928
The process_add_entry function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file.
- SUSE-SU-2016:1909
- SUSE-SU-2016:1909
- RHSA-2016:1844
- RHSA-2016:1844
- DSA-3657
- DSA-3657
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 91337
- 91337
- USN-3033-1
- USN-3033-1
- https://github.com/libarchive/libarchive/issues/550
- https://github.com/libarchive/libarchive/issues/550
- GLSA-201701-03
- GLSA-201701-03
Modified: 2024-11-21
CVE-2015-8929
Memory leak in the __archive_read_get_extract function in archive_read_extract2.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service via a tar file.
- SUSE-SU-2016:1909
- SUSE-SU-2016:1909
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- 91340
- 91340
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://github.com/libarchive/libarchive/issues/517
- https://github.com/libarchive/libarchive/issues/517
- GLSA-201701-03
- GLSA-201701-03
Modified: 2024-11-21
CVE-2015-8930
bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (infinite loop) via an ISO with a directory that is a member of itself.
- SUSE-SU-2016:1909
- SUSE-SU-2016:1909
- RHSA-2016:1844
- RHSA-2016:1844
- DSA-3657
- DSA-3657
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 91339
- 91339
- USN-3033-1
- USN-3033-1
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://github.com/libarchive/libarchive/issues/522
- https://github.com/libarchive/libarchive/issues/522
- GLSA-201701-03
- GLSA-201701-03
Modified: 2024-11-21
CVE-2015-8931
Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_read_support_format_mtree.c in libarchive before 3.2.0 allow remote attackers to have unspecified impact via a crafted mtree file, which triggers undefined behavior.
- SUSE-SU-2016:1909
- SUSE-SU-2016:1909
- RHSA-2016:1844
- RHSA-2016:1844
- DSA-3657
- DSA-3657
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 91338
- 91338
- USN-3033-1
- USN-3033-1
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://github.com/libarchive/libarchive/issues/539
- https://github.com/libarchive/libarchive/issues/539
- GLSA-201701-03
- GLSA-201701-03
- https://security-tracker.debian.org/tracker/CVE-2015-8931
- https://security-tracker.debian.org/tracker/CVE-2015-8931
Modified: 2024-11-21
CVE-2015-8932
The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left shift.
- SUSE-SU-2016:1909
- SUSE-SU-2016:1909
- RHSA-2016:1844
- RHSA-2016:1844
- RHSA-2016:1850
- RHSA-2016:1850
- DSA-3657
- DSA-3657
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 91424
- 91424
- USN-3033-1
- USN-3033-1
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://github.com/libarchive/libarchive/issues/547
- https://github.com/libarchive/libarchive/issues/547
- GLSA-201701-03
- GLSA-201701-03
- https://security-tracker.debian.org/tracker/CVE-2015-8932
- https://security-tracker.debian.org/tracker/CVE-2015-8932
Modified: 2024-11-21
CVE-2015-8933
Integer overflow in the archive_read_format_tar_skip function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file.
- SUSE-SU-2016:1909
- SUSE-SU-2016:1909
- DSA-3657
- DSA-3657
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- 91421
- 91421
- USN-3033-1
- USN-3033-1
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://github.com/libarchive/libarchive/issues/548
- https://github.com/libarchive/libarchive/issues/548
- GLSA-201701-03
- GLSA-201701-03
Modified: 2024-11-21
CVE-2015-8934
The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted rar file.
- SUSE-SU-2016:1909
- SUSE-SU-2016:1909
- RHSA-2016:1844
- RHSA-2016:1844
- DSA-3657
- DSA-3657
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- [oss-security] 20160617 Re: Many invalid memory access issues in libarchive
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 91409
- 91409
- USN-3033-1
- USN-3033-1
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
- https://github.com/libarchive/libarchive/issues/521
- https://github.com/libarchive/libarchive/issues/521
- GLSA-201701-03
- GLSA-201701-03
Modified: 2024-11-21
CVE-2016-1541
Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to execute arbitrary code via crafted entry-size values in a ZIP archive.
- openSUSE-SU-2016:1463
- openSUSE-SU-2016:1463
- openSUSE-SU-2016:1663
- openSUSE-SU-2016:1663
- RHSA-2016:1844
- RHSA-2016:1844
- DSA-3574
- DSA-3574
- VU#862384
- VU#862384
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 89355
- 89355
- SSA:2016-145-01
- SSA:2016-145-01
- USN-2981-1
- USN-2981-1
- https://github.com/libarchive/libarchive/commit/d0331e8e5b05b475f20b1f3101fe1ad772d7e7e7
- https://github.com/libarchive/libarchive/commit/d0331e8e5b05b475f20b1f3101fe1ad772d7e7e7
- https://github.com/libarchive/libarchive/issues/656
- https://github.com/libarchive/libarchive/issues/656
- GLSA-201701-03
- GLSA-201701-03
Modified: 2024-11-21
CVE-2016-4300
Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a 7zip file with a large number of substreams, which triggers a heap-based buffer overflow.
- http://blog.talosintel.com/2016/06/the-poisoned-archives.html
- http://blog.talosintel.com/2016/06/the-poisoned-archives.html
- RHSA-2016:1844
- RHSA-2016:1844
- DSA-3657
- DSA-3657
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 91326
- 91326
- http://www.talosintel.com/reports/TALOS-2016-0152/
- http://www.talosintel.com/reports/TALOS-2016-0152/
- https://bugzilla.redhat.com/show_bug.cgi?id=1348439
- https://bugzilla.redhat.com/show_bug.cgi?id=1348439
- https://github.com/libarchive/libarchive/commit/e79ef306afe332faf22e9b442a2c6b59cb175573
- https://github.com/libarchive/libarchive/commit/e79ef306afe332faf22e9b442a2c6b59cb175573
- https://github.com/libarchive/libarchive/issues/718
- https://github.com/libarchive/libarchive/issues/718
- GLSA-201701-03
- GLSA-201701-03
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00062&languageid=en-fr
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00062&languageid=en-fr
Modified: 2024-11-21
CVE-2016-4301
Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a crafted mtree file.
- http://blog.talosintel.com/2016/06/the-poisoned-archives.html
- http://blog.talosintel.com/2016/06/the-poisoned-archives.html
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- 91328
- 91328
- http://www.talosintel.com/reports/TALOS-2016-0153/
- http://www.talosintel.com/reports/TALOS-2016-0153/
- https://bugzilla.redhat.com/show_bug.cgi?id=1348441
- https://bugzilla.redhat.com/show_bug.cgi?id=1348441
- https://github.com/libarchive/libarchive/commit/a550daeecf6bc689ade371349892ea17b5b97c77
- https://github.com/libarchive/libarchive/commit/a550daeecf6bc689ade371349892ea17b5b97c77
- https://github.com/libarchive/libarchive/issues/715
- https://github.com/libarchive/libarchive/issues/715
- GLSA-201701-03
- GLSA-201701-03
Modified: 2024-11-21
CVE-2016-4302
Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a RAR file with a zero-sized dictionary.
- http://blog.talosintel.com/2016/06/the-poisoned-archives.html
- http://blog.talosintel.com/2016/06/the-poisoned-archives.html
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=1348444
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=1348444
- RHSA-2016:1844
- RHSA-2016:1844
- DSA-3657
- DSA-3657
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 91331
- 91331
- http://www.talosintel.com/reports/TALOS-2016-0154/
- http://www.talosintel.com/reports/TALOS-2016-0154/
- https://github.com/libarchive/libarchive/commit/05caadc7eedbef471ac9610809ba683f0c698700
- https://github.com/libarchive/libarchive/commit/05caadc7eedbef471ac9610809ba683f0c698700
- https://github.com/libarchive/libarchive/issues/719
- https://github.com/libarchive/libarchive/issues/719
- GLSA-201701-03
- GLSA-201701-03
Modified: 2024-11-21
CVE-2016-4809
The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a CPIO archive with a large symlink.
- RHSA-2016:1844
- RHSA-2016:1844
- RHSA-2016:1850
- RHSA-2016:1850
- DSA-3657
- DSA-3657
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 91813
- 91813
- https://bugzilla.redhat.com/show_bug.cgi?id=1347084
- https://bugzilla.redhat.com/show_bug.cgi?id=1347084
- https://github.com/libarchive/libarchive/commit/fd7e0c02
- https://github.com/libarchive/libarchive/commit/fd7e0c02
- https://github.com/libarchive/libarchive/issues/705
- https://github.com/libarchive/libarchive/issues/705
- GLSA-201701-03
- GLSA-201701-03
Modified: 2024-11-21
CVE-2016-5418
The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive file.
- RHSA-2016:1844
- RHSA-2016:1844
- RHSA-2016:1850
- RHSA-2016:1850
- [oss-security] 20160809 FreeBSD update components vulns (libarchive, bsdiff, portsnap)
- [oss-security] 20160809 FreeBSD update components vulns (libarchive, bsdiff, portsnap)
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 93165
- 93165
- RHSA-2016:1852
- RHSA-2016:1852
- RHSA-2016:1853
- RHSA-2016:1853
- https://bugzilla.redhat.com/show_bug.cgi?id=1362601
- https://bugzilla.redhat.com/show_bug.cgi?id=1362601
- https://gist.github.com/anonymous/e48209b03f1dd9625a992717e7b89c4f
- https://gist.github.com/anonymous/e48209b03f1dd9625a992717e7b89c4f
- https://github.com/libarchive/libarchive/commit/dfd6b54ce33960e420fb206d8872fb759b577ad9
- https://github.com/libarchive/libarchive/commit/dfd6b54ce33960e420fb206d8872fb759b577ad9
- https://github.com/libarchive/libarchive/issues/746
- https://github.com/libarchive/libarchive/issues/746
- GLSA-201701-03
- GLSA-201701-03
Modified: 2024-11-21
CVE-2016-5844
Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a crafted ISO file.
- RHSA-2016:1844
- RHSA-2016:1844
- RHSA-2016:1850
- RHSA-2016:1850
- DSA-3657
- DSA-3657
- [oss-security] 20160623 Out of bounds read and signed integer overflow in libarchive
- [oss-security] 20160623 Out of bounds read and signed integer overflow in libarchive
- [oss-security] 20160624 Re: Out of bounds read and signed integer overflow in libarchive
- [oss-security] 20160624 Re: Out of bounds read and signed integer overflow in libarchive
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 91808
- 91808
- 1036173
- 1036173
- https://blog.fuzzing-project.org/48-Out-of-bounds-read-and-signed-integer-overflow-in-libarchive.html
- https://blog.fuzzing-project.org/48-Out-of-bounds-read-and-signed-integer-overflow-in-libarchive.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1350280
- https://bugzilla.redhat.com/show_bug.cgi?id=1350280
- https://github.com/libarchive/libarchive/commit/3ad08e01b4d253c66ae56414886089684155af22
- https://github.com/libarchive/libarchive/commit/3ad08e01b4d253c66ae56414886089684155af22
- https://github.com/libarchive/libarchive/issues/717
- https://github.com/libarchive/libarchive/issues/717
- GLSA-201701-03
- GLSA-201701-03
Modified: 2024-11-21
CVE-2016-6250
Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors related to verifying filename lengths when writing an ISO9660 archive, which trigger a buffer overflow.
- RHSA-2016:1844
- RHSA-2016:1844
- [oss-security] 20160720 Buffer overflow in libarchive-3.2.0
- [oss-security] 20160720 Buffer overflow in libarchive-3.2.0
- [oss-security] 20160721 Re: Buffer overflow in libarchive-3.2.0
- [oss-security] 20160721 Re: Buffer overflow in libarchive-3.2.0
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 92036
- 92036
- 1036431
- 1036431
- https://bugzilla.redhat.com/show_bug.cgi?id=1347085
- https://bugzilla.redhat.com/show_bug.cgi?id=1347085
- https://github.com/libarchive/libarchive/commit/3014e198
- https://github.com/libarchive/libarchive/commit/3014e198
- https://github.com/libarchive/libarchive/files/295073/libarchiveOverflow.txt
- https://github.com/libarchive/libarchive/files/295073/libarchiveOverflow.txt
- https://github.com/libarchive/libarchive/issues/711
- https://github.com/libarchive/libarchive/issues/711
- GLSA-201701-03
- GLSA-201701-03
Modified: 2024-11-21
CVE-2016-7166
libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip file.
- RHSA-2016:1844
- RHSA-2016:1844
- RHSA-2016:1850
- RHSA-2016:1850
- [oss-security] 20160908 CVE request: libarchive (pre 3.2.0) denial of service with gzip quine
- [oss-security] 20160908 CVE request: libarchive (pre 3.2.0) denial of service with gzip quine
- [oss-security] 20160908 Re: CVE request: libarchive (pre 3.2.0) denial of service with gzip quine
- [oss-security] 20160908 Re: CVE request: libarchive (pre 3.2.0) denial of service with gzip quine
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 92901
- 92901
- https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=207362
- https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=207362
- https://bugzilla.redhat.com/show_bug.cgi?id=1347086
- https://bugzilla.redhat.com/show_bug.cgi?id=1347086
- https://github.com/libarchive/libarchive/commit/6e06b1c89dd0d16f74894eac4cfc1327a06ee4a0
- https://github.com/libarchive/libarchive/commit/6e06b1c89dd0d16f74894eac4cfc1327a06ee4a0
- https://github.com/libarchive/libarchive/issues/660
- https://github.com/libarchive/libarchive/issues/660
- GLSA-201701-03
- GLSA-201701-03