CVE-2006-5680
published 2006-11-09CVE-2006-5680: The libarchive library in FreeBSD 6-STABLE after 2006-09-05 and before 2006-11-08 allows context-dependent attackers to cause a denial of service (CPU…
PriorityP418medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.59%
72.9th percentile
The libarchive library in FreeBSD 6-STABLE after 2006-09-05 and before 2006-11-08 allows context-dependent attackers to cause a denial of service (CPU consumption) via a malformed archive that causes libarchive to skip a region past the actual end of the archive, which triggers an infinite loop that attempts to read more data.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libarchive | < libarchive 1.3.1-1 (bookworm) | libarchive 1.3.1-1 (bookworm) |
| freebsd | freebsd | — | — |
| libarchive | libarchive | >= 0 < 1.3.1-1 | 1.3.1-1 |
| libarchive | libarchive | >= 0 < 1.3.1-1 | 1.3.1-1 |
| libarchive | libarchive | >= 0 < 1.3.1-1 | 1.3.1-1 |
| libarchive | libarchive | >= 0 < 1.3.1-1 | 1.3.1-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
FreeBSD 6 denial of service (Nessus ID 24720 / XFDB-30137)
vuldb·2026-04-27·CVSS 5.0
CVE-2006-5680 [MEDIUM] FreeBSD 6 denial of service (Nessus ID 24720 / XFDB-30137)
A vulnerability was found in FreeBSD 6 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation results in denial of service.
This vulnerability was named CVE-2006-5680. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
GHSA
GHSA-9qcr-cp56-22qc: The libarchive library in FreeBSD 6-STABLE after 2006-09-05 and before 2006-11-08 allows context-dependent attackers to cause a denial of service (CPU
ghsa_unreviewed·2022-05-01
CVE-2006-5680 [MEDIUM] GHSA-9qcr-cp56-22qc: The libarchive library in FreeBSD 6-STABLE after 2006-09-05 and before 2006-11-08 allows context-dependent attackers to cause a denial of service (CPU
The libarchive library in FreeBSD 6-STABLE after 2006-09-05 and before 2006-11-08 allows context-dependent attackers to cause a denial of service (CPU consumption) via a malformed archive that causes libarchive to skip a region past the actual end of the archive, which triggers an infinite loop that attempts to read more data.
OSV
CVE-2006-5680: The libarchive library in FreeBSD 6-STABLE after 2006-09-05 and before 2006-11-08 allows context-dependent attackers to cause a denial of service (CPU
osv·2006-11-09·CVSS 5.0
CVE-2006-5680 [MEDIUM] CVE-2006-5680: The libarchive library in FreeBSD 6-STABLE after 2006-09-05 and before 2006-11-08 allows context-dependent attackers to cause a denial of service (CPU
The libarchive library in FreeBSD 6-STABLE after 2006-09-05 and before 2006-11-08 allows context-dependent attackers to cause a denial of service (CPU consumption) via a malformed archive that causes libarchive to skip a region past the actual end of the archive, which triggers an infinite loop that attempts to read more data.
BSD
FreeBSD-SA-06:24.libarchive: Infinite loop in corrupt archives handling in libarchive(3)
bsd_advisories·2006-11-08·CVSS 5.0
CVE-2006-5680 [MEDIUM] FreeBSD-SA-06:24.libarchive: Infinite loop in corrupt archives handling in libarchive(3)
FreeBSD-SA-06:24.libarchive Security Advisory
The FreeBSD Project
Topic: Infinite loop in corrupt archives handling in libarchive(3)
Category: core
Module: libarchive
Announced: 2006-11-08
Credits: Rink Springer
Affects: FreeBSD 6-STABLE after 2006-09-05 05:23:51 UTC
Corrected: 2006-11-08 14:05:40 UTC (RELENG_6, 6.2-RC1)
CVE Name: CVE-2006-5680
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
The libarchive library provides a flexible interface for reading and
writing streaming archive files such as tar and cpio, and has been the
basis for FreeBSD's implementation of the tar(1) utility since FreeBSD 5.3.
II. Problem Description
If the end of an archiv
Debian
CVE-2006-5680: libarchive - The libarchive library in FreeBSD 6-STABLE after 2006-09-05 and before 2006-11-0...
vendor_debian·2006·CVSS 5.0
CVE-2006-5680 [MEDIUM] CVE-2006-5680: libarchive - The libarchive library in FreeBSD 6-STABLE after 2006-09-05 and before 2006-11-0...
The libarchive library in FreeBSD 6-STABLE after 2006-09-05 and before 2006-11-08 allows context-dependent attackers to cause a denial of service (CPU consumption) via a malformed archive that causes libarchive to skip a region past the actual end of the archive, which triggers an infinite loop that attempts to read more data.
Scope: local
bookworm: resolved (fixed in 1.3.1-1)
bullseye: resolved (fixed in 1.3.1-1)
forky: resolved (fixed in 1.3.1-1)
sid: resolved (fixed in 1.3.1-1)
trixie: resolved (fixed in 1.3.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/22723http://secunia.com/advisories/22801http://security.freebsd.org/advisories/FreeBSD-SA-06:24.libarchive.aschttp://securitytracker.com/id?1017199http://www.securityfocus.com/bid/20961https://exchange.xforce.ibmcloud.com/vulnerabilities/30137http://secunia.com/advisories/22723http://secunia.com/advisories/22801http://security.freebsd.org/advisories/FreeBSD-SA-06:24.libarchive.aschttp://securitytracker.com/id?1017199http://www.securityfocus.com/bid/20961https://exchange.xforce.ibmcloud.com/vulnerabilities/30137
2006-11-09
Published