SUSE-SU-2016:2911-1
Dashboard / Vulnerabilities / SUSE-SU-2016:2911-1
SUSE-SU-2016:2911-1
Summary: Security update for libarchive
Details: This update for libarchive fixes several issues. These security issues were fixed: - CVE-2016-8687: Buffer overflow when printing a filename (bsc#1005070). - CVE-2016-8689: Heap overflow when reading corrupted 7Zip files (bsc#1005072). - CVE-2016-8688: Use after free because of incorrect calculation in next_line (bsc#1005076). - CVE-2016-5844: Integer overflow in the ISO parser in libarchive allowed remote attackers to cause a denial of service (application crash) via a crafted ISO file (bsc#986566). - CVE-2016-6250: Integer overflow in the ISO9660 writer in libarchive allowed remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors related to verifying filename lengths when writing an ISO9660 archive, which trigger a buffer overflow (bsc#989980). - CVE-2016-5418: The sandboxing code in libarchive mishandled hardlink archive entries of non-zero data size, which might allowed remote attackers to write to arbitrary files via a crafted archive file (bsc#998677).
References: https://www.suse.com/support/update/announcement/2016/suse-su-20162911-1/, https://bugzilla.suse.com/1005070, https://bugzilla.suse.com/1005072, https://bugzilla.suse.com/1005076, https://bugzilla.suse.com/986566, https://bugzilla.suse.com/989980, https://bugzilla.suse.com/998677, https://www.suse.com/security/cve/CVE-2015-2304, https://www.suse.com/security/cve/CVE-2016-5418, https://www.suse.com/security/cve/CVE-2016-5844, https://www.suse.com/security/cve/CVE-2016-6250, https://www.suse.com/security/cve/CVE-2016-8687, https://www.suse.com/security/cve/CVE-2016-8688, https://www.suse.com/security/cve/CVE-2016-8689
Affected packages
Package
Name: libarchive
Purl: pkg:rpm/suse/libarchive&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1
Affected ranges
Type: ECOSYSTEM
Events:
