SB2016080529 - Integer overflow in processing libarchive files in libarchive (Alpine package)
Published: August 5, 2016
Security Bulletin ID
SB2016080529
Severity
High
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Integer overflow in processing libarchive files (CVE-ID: CVE-2016-5844)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.The vulnerability exists due to boundary error when processing files in libarchive. A remote unauthenticated attacker can cause integer buffer overflow in choose_volume() by sending a specially crafted file to vulnerable server.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=87822f4ac4adaaafbbee3ffe58ab6eebdc12907e
- https://git.alpinelinux.org/aports/commit/?id=18e265665b4b640f80b99eabc7b585bb91923cd1
- https://git.alpinelinux.org/aports/commit/?id=9d0f5e1e02079c44a9c58169c8b78c743edaf7b8
- https://git.alpinelinux.org/aports/commit/?id=e9bdabd6e101ba083ed00a8ca911517facd8b1c7
- https://git.alpinelinux.org/aports/commit/?id=1245e3e71c664fc180d3a6f17a8aac878007bed2