SB2016080528 - Input validation error in libarchive (Alpine package)
Published: August 5, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2016-4809)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a CPIO archive with a large symlink.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=87822f4ac4adaaafbbee3ffe58ab6eebdc12907e
- https://git.alpinelinux.org/aports/commit/?id=18e265665b4b640f80b99eabc7b585bb91923cd1
- https://git.alpinelinux.org/aports/commit/?id=9d0f5e1e02079c44a9c58169c8b78c743edaf7b8
- https://git.alpinelinux.org/aports/commit/?id=e9bdabd6e101ba083ed00a8ca911517facd8b1c7
- https://git.alpinelinux.org/aports/commit/?id=1245e3e71c664fc180d3a6f17a8aac878007bed2