CVE-2016-8688

The mtree bidder in libarchive 3.2.1 does not keep track of line sizes when extending the read-ahead, which allows remote attackers to cause a denial of service (crash) via a crafted file, which triggers an invalid read in the (1) detect_form or (2) bid_entry function in libarchive/archive_read_support_format_mtree.c.
Configurations

Configuration 1 (hide)

cpe:2.3:a:libarchive:libarchive:3.2.1:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:opensuse:leap:42.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-02-15 19:59

Updated : 2023-12-10 12:01


NVD link : CVE-2016-8688

Mitre link : CVE-2016-8688

CVE.ORG link : CVE-2016-8688


JSON object : View

Products Affected

libarchive

  • libarchive

opensuse

  • leap
CWE
CWE-125

Out-of-bounds Read