libarchive CVE-2017-14166 Heap Buffer Overflow Vulnerability
BID:100841
Info
libarchive CVE-2017-14166 Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 100841 |
| Class: | Unknown |
| CVE: |
CVE-2017-14166 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 05 2017 12:00AM |
| Updated: | Sep 05 2017 12:00AM |
| Credit: | Agostino Sarubbo of Gentoo. |
| Vulnerable: |
Redhat Enterprise Linux 7 Redhat Enterprise Linux 6 libarchive libarchive 3.3.2 |
| Not Vulnerable: | |
Discussion
libarchive CVE-2017-14166 Heap Buffer Overflow Vulnerability
libarchive is prone to a heap-based buffer-overflow vulnerability.
An attacker can exploit this issue to crash the affected system, denying service to legitimate users.
libarchive version 3.3.2 is vulnerable; other versions may also be affected.
libarchive is prone to a heap-based buffer-overflow vulnerability.
An attacker can exploit this issue to crash the affected system, denying service to legitimate users.
libarchive version 3.3.2 is vulnerable; other versions may also be affected.
Exploit / POC
libarchive CVE-2017-14166 Heap Buffer Overflow Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
libarchive CVE-2017-14166 Heap Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
libarchive CVE-2017-14166 Heap Buffer Overflow Vulnerability
References:
References:
- libarchive Homepage (libarchive)
- Bug 1489852 - (CVE-2017-14166) CVE-2017-14166 libarchive: Heap-based buffer over (Redhat)
- commit fa7438a0ff4033e4741c807394a9af6207940d71 (Github)
- CVE-2017-14166 (Redhat)
- libarchive: heap-based buffer overflow in xml_data (archive_read_support_format_ (Gentoo)
- POC libarchive-heapoverflow-archive_read_support_format_xar (Github)