RHSA-2016:1850HighCVSS 7.5
Red Hat Security Advisory: libarchive security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2015-8920 — libarchive: Stack out of bounds read in ar parser CVE-2015-8921 — libarchive: Global out of bounds read in mtree parser CVE-2015-8932 — libarchive: Undefined behavior / invalid shiftleft in TAR parser CVE-2016-4809 — libarchive: Memory allocate error with symbolic links in cpio archives CVE-2016-5418 — libarchive: Archive Entry with type 1 (hardlink), but has a non-zero data size file overwrite CVE-2016-5844 — libarchive: undefined behaviour (integer overflow) in iso parser CVE-2016-7166 — libarchive: Denial of service using a crafted gzip file
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2016:1850
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1347084
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1347086
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1348416
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1348772
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1348780
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1350280
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1362601
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2016/rhsa-2016_1850.json