USN-3736-1
Dashboard / Vulnerabilities / USN-3736-1
USN-3736-1
Summary: libarchive vulnerabilities
Details: It was discovered that libarchive incorrectly handled certain archive files. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10209, CVE-2016-10349, CVE-2016-10350) Agostino Sarubbo discovered that libarchive incorrectly handled certain XAR files. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2017-14166) It was discovered that libarchive incorrectly handled certain files. A remote attacker could possibly use this issue to get access to sensitive information. (CVE-2017-14501, CVE-2017-14503)
References: https://ubuntu.com/security/notices/USN-3736-1, https://ubuntu.com/security/CVE-2016-10209, https://ubuntu.com/security/CVE-2016-10349, https://ubuntu.com/security/CVE-2016-10350, https://ubuntu.com/security/CVE-2017-14166, https://ubuntu.com/security/CVE-2017-14501, https://ubuntu.com/security/CVE-2017-14503
Affected packages
Package
Name: libarchive
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
