libarchive CVE-2016-10350 Heap Buffer Overflow Vulnerability
BID:100397
Info
libarchive CVE-2016-10350 Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 100397 |
| Class: | Unknown |
| CVE: |
CVE-2016-10350 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 12 2016 12:00AM |
| Updated: | Jun 12 2016 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Redhat Enterprise Linux 7 Redhat Enterprise Linux 6 libarchive libarchive 3.2.2 IBM Watson Explorer Foundational Components 11.0.2 IBM Watson Explorer Foundational Components 11.0.1 IBM Watson Explorer Foundational Components 11.0.0.3 IBM Watson Explorer Foundational Components 11.0.0.2 IBM Watson Explorer Foundational Components 11.0.0.1 IBM Watson Explorer Foundational Components 11.0.0.0 |
| Not Vulnerable: |
IBM Watson Explorer Foundational Components 11.0.2.1 |
Discussion
libarchive CVE-2016-10350 Heap Buffer Overflow Vulnerability
libarchive is prone to a heap-based buffer-overflow vulnerability.
An attacker can exploit this issue to crash the affected system, denying service to legitimate users.
libarchive version 3.2.2 is vulnerable; other versions may also be affected.
libarchive is prone to a heap-based buffer-overflow vulnerability.
An attacker can exploit this issue to crash the affected system, denying service to legitimate users.
libarchive version 3.2.2 is vulnerable; other versions may also be affected.
Solution / Fix
libarchive CVE-2016-10350 Heap Buffer Overflow Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
libarchive CVE-2016-10350 Heap Buffer Overflow Vulnerability
References:
References:
- libarchive Homepage (libarchive)
- 00106-libarchive-heapoverflow-archive_read_format_cab_read_header (Github)
- Bug 1449530 - (CVE-2016-10350) CVE-2016-10350 libarchive: Heap-based buffer over (Redhat)
- CVE-2016-10350 (Redhat)
- heap-buffer-overflow in archive_read_format_cab_read_header #835 (Github)
- swg22006995:Multiple vulnerabilities affect Watson Explorer (CVE-2016-8688, CVE- (IBM)