CVE-2011-1777
published 2012-04-13CVE-2011-1777: Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functions in archive_read_support_format_iso9660.c in libarchive through 2.8.5 allow…
PriorityP433medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.25%
90.0th percentile
Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functions in archive_read_support_format_iso9660.c in libarchive through 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ISO9660 image.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libarchive | < libarchive 2.8.5-5 (bookworm) | libarchive 2.8.5-5 (bookworm) |
| freebsd | libarchive | <= 2.8.5 | — |
| freebsd | libarchive | — | — |
| freebsd | libarchive | — | — |
| freebsd | libarchive | — | — |
| freebsd | libarchive | — | — |
| freebsd | libarchive | — | — |
| freebsd | libarchive | — | — |
| freebsd | libarchive | — | — |
| freebsd | libarchive | — | — |
| freebsd | libarchive | — | — |
| freebsd | libarchive | — | — |
| freebsd | libarchive | — | — |
| freebsd | libarchive | — | — |
| freebsd | libarchive | — | — |
| freebsd | libarchive | — | — |
| freebsd | libarchive | — | — |
| freebsd | libarchive | — | — |
| freebsd | libarchive | — | — |
| libarchive | libarchive | >= 0 < 2.8.5-5 | 2.8.5-5 |
| libarchive | libarchive | >= 0 < 2.8.5-5 | 2.8.5-5 |
| libarchive | libarchive | >= 0 < 2.8.5-5 | 2.8.5-5 |
| libarchive | libarchive | >= 0 < 2.8.5-5 | 2.8.5-5 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g8qh-wrpv-q82v: Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functions in archive_read_support_format_iso9660
ghsa_unreviewed·2022-05-14
CVE-2011-1777 [MEDIUM] CWE-119 GHSA-g8qh-wrpv-q82v: Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functions in archive_read_support_format_iso9660
Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functions in archive_read_support_format_iso9660.c in libarchive through 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ISO9660 image.
OSV
CVE-2011-1777: Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functions in archive_read_support_format_iso9660
osv·2012-04-13·CVSS 6.8
CVE-2011-1777 [MEDIUM] CVE-2011-1777: Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functions in archive_read_support_format_iso9660
Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functions in archive_read_support_format_iso9660.c in libarchive through 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ISO9660 image.
Ubuntu
libarchive vulnerabilities
vendor_ubuntu·2011-12-19·CVSS 6.8
CVE-2011-1777 [MEDIUM] libarchive vulnerabilities
Title: libarchive vulnerabilities
Summary: libarchive could be made to crash or run programs as your login if it
opened a specially crafted file.
It was discovered that libarchive incorrectly handled certain ISO 9660
image files. If a user were tricked into using a specially crafted
ISO 9660 image file, a remote attacker could cause libarchive to crash or
possibly execute arbitrary code with user privileges. (CVE-2011-1777)
It was discovered that libarchive incorrectly handled certain tar archive
files. If a user were tricked into using a specially crafted tar file, a
remote attacker could cause libarchive to crash or possibly execute
arbitrary code with user privileges. (CVE-2011-1778)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2011-1777: libarchive - Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functio...
vendor_debian·2011·CVSS 6.8
CVE-2011-1777 [MEDIUM] CVE-2011-1777: libarchive - Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functio...
Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functions in archive_read_support_format_iso9660.c in libarchive through 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ISO9660 image.
Scope: local
bookworm: resolved (fixed in 2.8.5-5)
bullseye: resolved (fixed in 2.8.5-5)
forky: resolved (fixed in 2.8.5-5)
sid: resolved (fixed in 2.8.5-5)
trixie: resolved (fixed in 2.8.5-5)
Red Hat
Libarchive multiple security issues
vendor_redhat·2010-12-30·CVSS 6.8
CVE-2011-1777 [MEDIUM] Libarchive multiple security issues
Libarchive multiple security issues
Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functions in archive_read_support_format_iso9660.c in libarchive through 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ISO9660 image.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-4024 squashfs-tools: remote arbitrary code execution via crafted list file
bugzilla·2012-07-23·CVSS 6.8
CVE-2012-4024 [MEDIUM] CVE-2012-4024 squashfs-tools: remote arbitrary code execution via crafted list file
CVE-2012-4024 squashfs-tools: remote arbitrary code execution via crafted list file
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-4024 to
the following vulnerability:
Name: CVE-2012-4024
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4024
Assigned: 20120716
Reference: http://sourceforge.net/mailarchive/forum.php?thread_name=CAAoG81HL9oP8roPLLhftTSXTzSD%2BZcR66PRkVU%3Df76W3Mjde_w%40mail.gmail.com&forum_name=squashfs-devel
Reference: http://www.osvdb.org/83898
Stack-based buffer overflow in the get_component function in
unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote
attackers to execute arbitrary code via a crafted list file (aka a
crafted file for the -ef option). NOTE: probably in most cases, the
list file is a trusted file const
Bugzilla
CVE-2010-4666 CVE-2011-1777 CVE-2011-1778 CVE-2011-1779 Libarchive multiple security issues [epel-5]
bugzilla·2012-01-12·CVSS 7.5
CVE-2010-4666 [HIGH] CVE-2010-4666 CVE-2011-1777 CVE-2011-1778 CVE-2011-1779 Libarchive multiple security issues [epel-5]
CVE-2010-4666 CVE-2011-1777 CVE-2011-1778 CVE-2011-1779 Libarchive multiple security issues [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/up
Bugzilla
CVE-2011-4111 qemu: ccid: buffer overflow in handling of VSC_ATR message
bugzilla·2011-11-04·CVSS 6.8
CVE-2011-4111 [MEDIUM] CVE-2011-4111 qemu: ccid: buffer overflow in handling of VSC_ATR message
CVE-2011-4111 qemu: ccid: buffer overflow in handling of VSC_ATR message
A flaw was found in the way QEMU handled VSC_ATR messages when CCID card passthru device was used. A malicious client could use this flaw to crash the QEMU process or, potentially, escalate his privileges.
Discussion:
Created attachment 532114
Proposed patch
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:1777 https://rhn.redhat.com/errata/RHSA-2011-1777.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux EUS 6.1
Via RHSA-2011:1801 https://rhn.redhat.com/errata/RHSA-2011-1801.html
---
Statement:
This issue does not affect versions of kvm package as shipped with Red Hat
Enterprise Linux 5.
Bugzilla
CVE-2010-4666 CVE-2011-1777 CVE-2011-1778 CVE-2011-1779 Libarchive multiple security issues [fedora-all]
bugzilla·2011-05-18·CVSS 7.5
CVE-2010-4666 [HIGH] CVE-2010-4666 CVE-2011-1777 CVE-2011-1778 CVE-2011-1779 Libarchive multiple security issues [fedora-all]
CVE-2010-4666 CVE-2011-1777 CVE-2011-1778 CVE-2011-1779 Libarchive multiple security issues [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=705849
Please not
Bugzilla
CVE-2010-4666 CVE-2011-1777 CVE-2011-1778 CVE-2011-1779 Libarchive multiple security issues
bugzilla·2011-05-18·CVSS 7.5
CVE-2010-4666 [HIGH] CVE-2010-4666 CVE-2011-1777 CVE-2011-1778 CVE-2011-1779 Libarchive multiple security issues
CVE-2010-4666 CVE-2011-1777 CVE-2011-1778 CVE-2011-1779 Libarchive multiple security issues
A number of flaws have been corrected in upstream libarchive that have not yet been included in a public release of libarchive (latest version is 2.8.4).
A buffer overflow at reading bit lengths of huffman code of LZX when reading a broken CAB file (CVE-2010-4666) [1].
Buffer overflows in various functions related to reading archives (in archive_read_support_format_iso9660.c) (CVE-2011-1777) [2].
Buffer overflow in reading tar archives (CVE-2011-1778) [3].
Use-after-free bugs (CVE-2011-1779) [4].
[1] http://code.google.com/p/libarchive/source/detail?r=2842
[2] http://code.google.com/p/libarchive/source/detail?r=3158
[3] http://code.google.com/p/libarchive/source/detail?r=3160
[4] http://code.g
http://code.google.com/p/libarchive/source/detail?r=3158http://lists.apple.com/archives/security-announce/2012/May/msg00001.htmlhttp://secunia.com/advisories/48034http://support.apple.com/kb/HT5281http://www.debian.org/security/2012/dsa-2413https://bugzilla.redhat.com/show_bug.cgi?id=705849https://rhn.redhat.com/errata/RHSA-2011-1507.htmlhttp://code.google.com/p/libarchive/source/detail?r=3158http://lists.apple.com/archives/security-announce/2012/May/msg00001.htmlhttp://secunia.com/advisories/48034http://support.apple.com/kb/HT5281http://www.debian.org/security/2012/dsa-2413https://bugzilla.redhat.com/show_bug.cgi?id=705849https://rhn.redhat.com/errata/RHSA-2011-1507.html
2012-04-13
Published