CVE-2016-1541 — Improper Input Validation in Libarchive
Severity
8.8HIGHNVD
EPSS
9.3%
top 7.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 7
Latest updateMay 14
Description
Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to execute arbitrary code via crafted entry-size values in a ZIP archive.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages4 packages
🔴Vulnerability Details
3📋Vendor Advisories
3📄Research Papers
1💬Community
4Bugzilla▶
CVE-2016-1541 libarchive: heap-based buffer overflow due to improper input validation [epel-5]↗2016-05-12
Bugzilla▶
CVE-2016-1541 libarchive: heap-based buffer overflow due to improper input validation [fedora-all]↗2016-05-09
Bugzilla▶
CVE-2016-1541 libarchive: heap-based buffer overflow due to improper input validation [epel-6]↗2016-05-09