MGASA-2017-0132
Dashboard / Vulnerabilities / MGASA-2017-0132
MGASA-2017-0132
Summary: Updated libarchive packages fix security vulnerabilities
Details: The archive_wstring_append_from_mbs function in archive_string.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive file. (CVE-2016-10209) The archive_le32dec function in archive_endian.h in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file. (CVE-2016-10349) The archive_read_format_cab_read_header function in archive_read_support_format_cab.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file. (CVE-2016-10350)
References: https://advisories.mageia.org/MGASA-2017-0132.html, https://bugs.mageia.org/show_bug.cgi?id=20723, http://openwall.com/lists/oss-security/2017/05/01/12
Affected packages
Package
Name: libarchive
Purl: pkg:rpm/mageia/libarchive?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
