libarchive CVE-2016-10349 Heap Buffer Overflow Vulnerability
BID:100347
Info
libarchive CVE-2016-10349 Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 100347 |
| Class: | Unknown |
| CVE: |
CVE-2016-10349 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 09 2017 12:00AM |
| Updated: | Aug 09 2017 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
libarchive libarchive 3.2.2 IBM Watson Explorer Foundational Components 11.0.2 IBM Watson Explorer Foundational Components 11.0.1 IBM Watson Explorer Foundational Components 11.0.0.3 IBM Watson Explorer Foundational Components 11.0.0.2 IBM Watson Explorer Foundational Components 11.0.0.1 IBM Watson Explorer Foundational Components 11.0.0.0 |
| Not Vulnerable: |
IBM Watson Explorer Foundational Components 11.0.2.1 |
Discussion
libarchive CVE-2016-10349 Heap Buffer Overflow Vulnerability
libarchive is prone to a heap-based buffer-overflow vulnerability.
An attacker can exploit this issue to crash the affected system, denying service to legitimate users.
libarchive version 3.2.2 is vulnerable; other versions may also be affected.
libarchive is prone to a heap-based buffer-overflow vulnerability.
An attacker can exploit this issue to crash the affected system, denying service to legitimate users.
libarchive version 3.2.2 is vulnerable; other versions may also be affected.
Solution / Fix
libarchive CVE-2016-10349 Heap Buffer Overflow Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
libarchive CVE-2016-10349 Heap Buffer Overflow Vulnerability
References:
References:
- libarchive Homepage (libarchive)
- 00105-libarchive-heapoverflow-archive_le32dec (Github)
- Bug 1449528 - (CVE-2016-10349) CVE-2016-10349 libarchive: Heap-based buffer over (Redhat)
- CVE-2016-10349 (Redhat)
- heap-buffer-overflow in archive_le32dec #834 (Github)
- swg22006995:Multiple vulnerabilities affect Watson Explorer (CVE-2016-8688, CVE- (IBM)