UBUNTU-CVE-2017-14166
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-14166
UBUNTU-CVE-2017-14166
Summary:
Details: libarchive 3.3.2 allows remote attackers to cause a denial of service (xml_data heap-based buffer over-read and application crash) via a crafted xar archive, related to the mishandling of empty strings in the atol8 function in archive_read_support_format_xar.c.
References: https://ubuntu.com/security/CVE-2017-14166, http://www.openwall.com/lists/oss-security/2017/09/06/5, https://blogs.gentoo.org/ago/2017/09/06/libarchive-heap-based-buffer-overflow-in-xml_data-archive_read_support_format_xar-c/, https://ubuntu.com/security/notices/USN-3736-1, https://www.cve.org/CVERecord?id=CVE-2017-14166
Affected packages
Package
Name: libarchive
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
