CVE-2016-8688

The mtree bidder in libarchive 3.2.1 does not keep track of line sizes when extending the read-ahead, which allows remote attackers to cause a denial of service (crash) via a crafted file, which triggers an invalid read in the (1) detect_form or (2) bid_entry function in libarchive/archive_read_support_format_mtree.c.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:libarchive:libarchive:3.2.1:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:opensuse:leap:42.2:*:*:*:*:*:*:*

Information

Published : 2017-02-15 11:59

Updated : 2018-11-30 03:29


NVD link : CVE-2016-8688

Mitre link : CVE-2016-8688


JSON object : View

CWE
CWE-125

Out-of-bounds Read

Advertisement

dedicated server usa

Products Affected

libarchive

  • libarchive

opensuse

  • leap