CVE-2013-0211
published 2013-09-30CVE-2013-0211: Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit…
PriorityP426medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.93%
89.2th percentile
Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of service (crash) via unspecified vectors, which triggers an improper conversion between unsigned and signed types, leading to a buffer overflow.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libarchive | < libarchive 3.0.4-3 (bookworm) | libarchive 3.0.4-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| freebsd | freebsd | — | — |
| libarchive | libarchive | <= 3.1.2 | — |
| libarchive | libarchive | >= 0 < 3.0.4-3 | 3.0.4-3 |
| libarchive | libarchive | >= 0 < 3.0.4-3 | 3.0.4-3 |
| libarchive | libarchive | >= 0 < 3.0.4-3 | 3.0.4-3 |
| libarchive | libarchive | >= 0 < 3.0.4-3 | 3.0.4-3 |
| libarchive | libarchive | >= 0 < 3.1.2-7ubuntu2.1 | 3.1.2-7ubuntu2.1 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c9hm-r59j-h433: Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip
ghsa_unreviewed·2022-05-05
CVE-2013-0211 [MEDIUM] GHSA-c9hm-r59j-h433: Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip
Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of service (crash) via unspecified vectors, which triggers an improper conversion between unsigned and signed types, leading to a buffer overflow.
OSV
libarchive vulnerabilities
osv·2015-03-25·CVSS 5.0
CVE-2015-2304 [MEDIUM] libarchive vulnerabilities
libarchive vulnerabilities
It was discovered that the libarchive bsdcpio utility extracted absolute
paths by default without using the --insecure flag, contrary to
expectations. If a user or automated system were tricked into extracting
cpio archives containing absolute paths, a remote attacker may be able to
write to arbitrary files. (CVE-2015-2304)
Fabian Yamaguchi discovered that libarchive incorrectly handled certain
type conversions. A remote attacker could possibly use this issue to cause
libarchive to crash, resulting in a denial of service. This issue only
affected Ubuntu 12.04 LTS. (CVE-2013-0211)
OSV
CVE-2013-0211: Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip
osv·2013-09-30·CVSS 5.0
CVE-2013-0211 [MEDIUM] CVE-2013-0211: Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip
Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of service (crash) via unspecified vectors, which triggers an improper conversion between unsigned and signed types, leading to a buffer overflow.
BSD
FreeBSD-SA-16:23.libarchive: Buffer overflow in libarchive(3)
bsd_advisories·2016-05-31·CVSS 5.0
CVE-2013-0211 [MEDIUM] FreeBSD-SA-16:23.libarchive: Buffer overflow in libarchive(3)
FreeBSD-SA-16:23.libarchive Security Advisory
The FreeBSD Project
Topic: Buffer overflow in libarchive(3)
Category: contrib
Module: libarchive
Announced: 2016-05-31
Affects: FreeBSD 9.3
Corrected: 2016-05-21 09:27:30 UTC (stable/9, 9.3-STABLE)
2016-05-31 16:23:56 UTC (releng/9.3, 9.3-RELEASE-p43)
CVE Name: CVE-2013-0211
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
The libarchive(3) library provides a flexible interface for reading and
writing streaming archive files such as tar and cpio, and has been the
basis for FreeBSD's implementation of the tar(1) and cpio(1) utilities
since FreeBSD 5.3.
II. Problem Description
An integer signedness error in
Ubuntu
libarchive vulnerabilities
vendor_ubuntu·2015-03-25·CVSS 5.0
CVE-2013-0211 [MEDIUM] libarchive vulnerabilities
Title: libarchive vulnerabilities
Summary: libarchive could be made to crash or overwrite files.
It was discovered that the libarchive bsdcpio utility extracted absolute
paths by default without using the --insecure flag, contrary to
expectations. If a user or automated system were tricked into extracting
cpio archives containing absolute paths, a remote attacker may be able to
write to arbitrary files. (CVE-2015-2304)
Fabian Yamaguchi discovered that libarchive incorrectly handled certain
type conversions. A remote attacker could possibly use this issue to cause
libarchive to crash, resulting in a denial of service. This issue only
affected Ubuntu 12.04 LTS. (CVE-2013-0211)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libarchive: read buffer overflow on 64-bit systems
vendor_redhat·2013-03-25·CVSS 5.0
CVE-2013-0211 [MEDIUM] libarchive: read buffer overflow on 64-bit systems
libarchive: read buffer overflow on 64-bit systems
Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of service (crash) via unspecified vectors, which triggers an improper conversion between unsigned and signed types, leading to a buffer overflow.
Package: libarchive (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2013-0211: libarchive - Integer signedness error in the archive_write_zip_data function in archive_write...
vendor_debian·2013·CVSS 5.0
CVE-2013-0211 [MEDIUM] CVE-2013-0211: libarchive - Integer signedness error in the archive_write_zip_data function in archive_write...
Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of service (crash) via unspecified vectors, which triggers an improper conversion between unsigned and signed types, leading to a buffer overflow.
Scope: local
bookworm: resolved (fixed in 3.0.4-3)
bullseye: resolved (fixed in 3.0.4-3)
forky: resolved (fixed in 3.0.4-3)
sid: resolved (fixed in 3.0.4-3)
trixie: resolved (fixed in 3.0.4-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0211 libarchive: read buffer overflow on 64-bit systems [epel-5]
bugzilla·2013-03-25·CVSS 5.0
CVE-2013-0211 [MEDIUM] CVE-2013-0211 libarchive: read buffer overflow on 64-bit systems [epel-5]
CVE-2013-0211 libarchive: read buffer overflow on 64-bit systems [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for li
Bugzilla
CVE-2013-0211 libarchive: read buffer overflow on 64-bit systems [fedora-all]
bugzilla·2013-03-25·CVSS 5.0
CVE-2013-0211 [MEDIUM] CVE-2013-0211 libarchive: read buffer overflow on 64-bit systems [fedora-all]
CVE-2013-0211 libarchive: read buffer overflow on 64-bit systems [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue aff
Bugzilla
CVE-2013-0211 libarchive: read buffer overflow on 64-bit systems [fedora-all]
bugzilla·2013-03-25·CVSS 5.0
CVE-2013-0211 [MEDIUM] CVE-2013-0211 libarchive: read buffer overflow on 64-bit systems [fedora-all]
CVE-2013-0211 libarchive: read buffer overflow on 64-bit systems [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue aff
Bugzilla
CVE-2012-6115 rhev: rhevm-manage-domains logs admin passwords
bugzilla·2013-01-30·CVSS 2.1
CVE-2012-6115 [LOW] CVE-2012-6115 rhev: rhevm-manage-domains logs admin passwords
CVE-2012-6115 rhev: rhevm-manage-domains logs admin passwords
It was discovered that rhevm-manage-domains, when performing validate action,
logged administrative passwords to a world readable log file. A local
attacker could use this flaw to control systems deployed and managed by RHEV.
Upstream commit:
http://gerrit.ovirt.org/gitweb?p=ovirt-engine.git;a=commit;h=e8c72daec4efa8be0fcd8ea55c41e855ddd8eedf
Acknowledgements:
This issue was discovered by Andrew Cathrow of Red Hat.
Discussion:
This issue has been addressed in following products:
RHEV Manager version 3.1
Via RHSA-2013:0211 https://rhn.redhat.com/errata/RHSA-2013-0211.html
Bugzilla
CVE-2013-0211 libarchive: read buffer overflow on 64-bit systems
bugzilla·2013-01-22·CVSS 5.0
CVE-2013-0211 [MEDIUM] CVE-2013-0211 libarchive: read buffer overflow on 64-bit systems
CVE-2013-0211 libarchive: read buffer overflow on 64-bit systems
Fabian Yamaguchi reported a read buffer overflow flaw in libarchive on 64-bit systems where sizeof(size_t) is equal to 8. In the archive_write_zip_data() function in libarchive/archive_write_set_format_zip.c, the "s" parameter is of type size_t (64 bit, unsigned) and is cast to a 64 bit signed integer. If "s" is larger than MAX_INT, it will not be set to "zip->remaining_data_bytes" even though it is larger than "zip->remaining_data_bytes", which leads to a buffer overflow when calling deflate().
This can lead to a segfault in an application that uses libarchive to create ZIP archives.
Discussion:
Created attachment 685479
proposed upstream patch
---
This issue is now public via:
https://github.com/libarchive/libarchive
Bugzilla
CVE-2013-0168 rhev-m: insufficient MoveDisk target domain permission checks
bugzilla·2013-01-09·CVSS 4.0
CVE-2013-0168 [MEDIUM] CVE-2013-0168 rhev-m: insufficient MoveDisk target domain permission checks
CVE-2013-0168 rhev-m: insufficient MoveDisk target domain permission checks
A flaw was found in the way MoveDisk command checks permissions on target storage domain. A privileged user (storage admin of other storage domain) can use this flaw to conduct denial of service attack on the target domain by exhausting the available free space.
Acknowledgements:
This issue was discovered by Ondrej Machacek of Red Hat.
Discussion:
This issue has been addressed in following products:
RHEV Manager version 3.1
Via RHSA-2013:0211 https://rhn.redhat.com/errata/RHSA-2013-0211.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101687.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/101700.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/101872.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/101876.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00065.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:147http://www.securityfocus.com/bid/58926http://www.securitytracker.com/id/1035995http://www.ubuntu.com/usn/USN-2549-1https://bugzilla.redhat.com/show_bug.cgi?id=902998https://github.com/libarchive/libarchive/commit/22531545514043e04633e1c015c7540b9de9dbe4https://www.freebsd.org/security/advisories/FreeBSD-SA-16:23.libarchive.aschttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/101687.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/101700.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/101872.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/101876.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00065.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:147http://www.securityfocus.com/bid/58926http://www.securitytracker.com/id/1035995http://www.ubuntu.com/usn/USN-2549-1https://bugzilla.redhat.com/show_bug.cgi?id=902998https://github.com/libarchive/libarchive/commit/22531545514043e04633e1c015c7540b9de9dbe4https://www.freebsd.org/security/advisories/FreeBSD-SA-16:23.libarchive.asc
2013-09-30
Published