Red Hat Security Advisory: libarchive security update
🔗 CVE IDs covered (23)
📋 Description
CVE-2015-8916 — libarchive: NULL pointer access in RAR parser through bsdtar CVE-2015-8917 — libarchive: NULL pointer access in CAB parser CVE-2015-8919 — libarchive: Heap out of bounds read in LHA/LZH parser CVE-2015-8920 — libarchive: Stack out of bounds read in ar parser CVE-2015-8921 — libarchive: Global out of bounds read in mtree parser CVE-2015-8922 — libarchive: NULL pointer access in 7z parser CVE-2015-8923 — libarchive: Unclear crashes in ZIP parser CVE-2015-8924 — libarchive: Heap out of bounds read in TAR parser CVE-2015-8925 — libarchive: Unclear invalid memory read in mtree parser CVE-2015-8926 — libarchive: NULL pointer access in RAR parser CVE-2015-8928 — libarchive: Heap out of bounds read in mtree parser CVE-2015-8930 — libarchive: Endless loop in ISO parser CVE-2015-8931 — libarchive: Undefined behavior (signed integer overflow) in mtree parser CVE-2015-8932 — libarchive: Undefined behavior / invalid shiftleft in TAR parser CVE-2015-8934 — libarchive: out of bounds heap read in RAR parser CVE-2016-1541 — libarchive: zip_read_mac_metadata() heap-based buffer overflow CVE-2016-4300 — libarchive: Heap buffer overflow vulnerability in the 7zip read_SubStreamsInfo CVE-2016-4302 — libarchive: Heap buffer overflow in the Rar decompression functionality CVE-2016-4809 — libarchive: Memory allocate error with symbolic links in cpio archives CVE-2016-5418 — libarchive: Archive Entry with type 1 (hardlink), but has a non-zero data size file overwrite CVE-2016-5844 — libarchive: undefined behaviour (integer overflow) in iso parser CVE-2016-6250 — libarchive: Buffer overflow when writing large iso9660 containers CVE-2016-7166 — libarchive: Denial of service using a crafted gzip file
🔗 References (26)
- selfhttps://access.redhat.com/errata/RHSA-2016:1844
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1334211
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1347084
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1347085
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1347086
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1348412
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1348413
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1348414
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1348416
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1348419
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1348421
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1348423
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1348424
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1348429
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1348439
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1348444
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1348772
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1348773
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1348779
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1348780
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1349204
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1349229
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1350280
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1362601
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2016/rhsa-2016_1844.json