Libarchive

Libarchive

77 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.54%
  • Veröffentlicht 21.09.2016 14:25:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a CPIO archive with a large symlink.

Exploit
  • EPSS 1.21%
  • Veröffentlicht 21.09.2016 14:25:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a RAR file with a zero-sized dictionary.

Exploit
  • EPSS 1.37%
  • Veröffentlicht 21.09.2016 14:25:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a crafted mtree file.

Exploit
  • EPSS 0.91%
  • Veröffentlicht 21.09.2016 14:25:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a 7zip file with a large number of substreams, which triggers a heap-based buf...

Exploit
  • EPSS 1.36%
  • Veröffentlicht 20.09.2016 14:15:20
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted rar file.

Exploit
  • EPSS 0.31%
  • Veröffentlicht 20.09.2016 14:15:19
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Integer overflow in the archive_read_format_tar_skip function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file.

Exploit
  • EPSS 0.27%
  • Veröffentlicht 20.09.2016 14:15:18
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_read_support_format_mtree.c in libarchive before 3.2.0 allow remote attackers to have unspecified impact via a crafted mtree file, which triggers undefin...

Exploit
  • EPSS 0.56%
  • Veröffentlicht 20.09.2016 14:15:18
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left shift.

  • EPSS 4.8%
  • Veröffentlicht 20.09.2016 14:15:17
  • Zuletzt bearbeitet 06.05.2026 22:30:45

bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (infinite loop) via an ISO with a directory that is a member of itself.

Exploit
  • EPSS 0.25%
  • Veröffentlicht 20.09.2016 14:15:16
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Memory leak in the __archive_read_get_extract function in archive_read_extract2.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service via a tar file.