CVE-2006-5680Infinite Loop in Libarchive

5 documents5 sources
Severity
5.0MEDIUMNVD
EPSS
0.8%
top 26.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 9
Latest updateMay 1

Description

The libarchive library in FreeBSD 6-STABLE after 2006-09-05 and before 2006-11-08 allows context-dependent attackers to cause a denial of service (CPU consumption) via a malformed archive that causes libarchive to skip a region past the actual end of the archive, which triggers an infinite loop that attempts to read more data.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

debiandebian/libarchive< libarchive 1.3.1-1 (bookworm)
Debianlibarchive/libarchive< 1.3.1-1+3

Also affects: Freebsd 6

🔴Vulnerability Details

2
GHSA
GHSA-9qcr-cp56-22qc: The libarchive library in FreeBSD 6-STABLE after 2006-09-05 and before 2006-11-08 allows context-dependent attackers to cause a denial of service (CPU2022-05-01
OSV
CVE-2006-5680: The libarchive library in FreeBSD 6-STABLE after 2006-09-05 and before 2006-11-08 allows context-dependent attackers to cause a denial of service (CPU2006-11-09

📋Vendor Advisories

2
BSD
FreeBSD-SA-06:24.libarchive: Infinite loop in corrupt archives handling in libarchive(3)2006-11-08
Debian
CVE-2006-5680: libarchive - The libarchive library in FreeBSD 6-STABLE after 2006-09-05 and before 2006-11-0...2006