7.5
CVE-2016-5418
- EPSS 4.71%
- Veröffentlicht 21.09.2016 14:25:13
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Hpc Node Version 6.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 6.0
Libarchive ≫ Libarchive Version <= 3.2.0
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Hpc Node Version 7.0
Redhat ≫ Enterprise Linux Hpc Node Eus Version 7.2
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server Aus Version 7.2
Redhat ≫ Enterprise Linux Server Eus Version 7.2
Redhat ≫ Enterprise Linux Workstation Version 7.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.71% | 0.907 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
https://security.gentoo.org/glsa/201701-03
http://rhn.redhat.com/errata/RHSA-2016-1844.html
http://rhn.redhat.com/errata/RHSA-2016-1850.html
http://www.openwall.com/lists/oss-security/2016/08/09/2
http://www.securityfocus.com/bid/93165
https://access.redhat.com/errata/RHSA-2016:1852
https://access.redhat.com/errata/RHSA-2016:1853
https://bugzilla.redhat.com/show_bug.cgi?id=1362601
https://gist.github.com/anonymous/e48209b03f1dd9625a992717e7b89c4f
https://github.com/libarchive/libarchive/commit/dfd6b54ce33960e420fb206d8872fb759b577ad9
https://github.com/libarchive/libarchive/issues/746