SB2017020106 - Out-of-bounds read in libarchive (Alpine package)
Published: February 1, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2017-5601)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-of-bounds read memory access and subsequently cause a crash via a specially crafted archive.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=656d3e5f5e57245f879ebe44952f4de997a8007d
- https://git.alpinelinux.org/aports/commit/?id=0f519752df2395117bc1161340bdfa3811c54eab
- https://git.alpinelinux.org/aports/commit/?id=d029d2538b849de290717aa7df42bc809329b0d9
- https://git.alpinelinux.org/aports/commit/?id=2633b787490d2fbf07717ea3fbe19834224a1ad9