[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

[3.4] libarchive: heap-based buffer overflow due to improper input validation (CVE-2016-1541)

ID: oval:org.secpod.oval:def:1800217Date: (C)2018-03-29   (M)2022-09-23
Class: PATCHFamily: unix




A crafted zip file can provide an incorrect compressed size, which may allow an attacker to place arbitrary code on the heap and execute it in the context of the current user. The user must be coerced into unzipping the crafted zip file. Fixed In Version: libarchive 3.2.0

Platform:
Alpine Linux 3.4
Product:
libarchive
Reference:
5561
CVE-2016-1541
CVE    1
CVE-2016-1541
CPE    3
cpe:/a:libarchive:libarchive
cpe:/o:alpinelinux:alpine_linux:3.4
cpe:/a:libarchive:libarchive:3.1.901a

© SecPod Technologies