CVE-2016-4301
published 2016-09-21CVE-2016-4301: Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attackers to execute…
PriorityP337high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
3.72%
88.6th percentile
Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a crafted mtree file.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libarchive | < libarchive 3.2.1-1 (bookworm) | libarchive 3.2.1-1 (bookworm) |
| libarchive | libarchive | <= 3.2.0 | — |
| libarchive | libarchive | >= 0 < 3.2.1-1 | 3.2.1-1 |
| libarchive | libarchive | >= 0 < 3.2.1-1 | 3.2.1-1 |
| libarchive | libarchive | >= 0 < 3.2.1-1 | 3.2.1-1 |
| libarchive | libarchive | >= 0 < 3.2.1-1 | 3.2.1-1 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libarchive: Stack buffer overflow in the mtree parse_device
vendor_redhat·2016-06-19·CVSS 7.8
CVE-2016-4301 [HIGH] CWE-121 libarchive: Stack buffer overflow in the mtree parse_device
libarchive: Stack buffer overflow in the mtree parse_device
Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a crafted mtree file.
An exploitable stack based buffer overflow vulnerability exists in the mtree parse_device functionality of libarchive. A specially crafted mtree file can cause a buffer overflow resulting in memory corruption and potential code execution in the context of the application.
Package: libarchive (Red Hat Enterprise Linux 6) - Not affected
Package: libarchive (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2016-4301: libarchive - Stack-based buffer overflow in the parse_device function in archive_read_support...
vendor_debian·2016·CVSS 7.8
CVE-2016-4301 [HIGH] CVE-2016-4301: libarchive - Stack-based buffer overflow in the parse_device function in archive_read_support...
Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a crafted mtree file.
Scope: local
bookworm: resolved (fixed in 3.2.1-1)
bullseye: resolved (fixed in 3.2.1-1)
forky: resolved (fixed in 3.2.1-1)
sid: resolved (fixed in 3.2.1-1)
trixie: resolved (fixed in 3.2.1-1)
GHSA
GHSA-r3m8-9hr7-7xwr: Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree
ghsa_unreviewed·2022-05-17
CVE-2016-4301 [HIGH] CWE-119 GHSA-r3m8-9hr7-7xwr: Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree
Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a crafted mtree file.
OSV
CVE-2016-4301: Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree
osv·2016-09-21·CVSS 7.8
CVE-2016-4301 [HIGH] CVE-2016-4301: Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree
Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a crafted mtree file.
No detection rules found.
No public exploits indexed.
Talos
The Poisoned Archives
blogs_talos·2016-06-21·CVSS 7.8
[HIGH] The Poisoned Archives
## The Poisoned Archives
Vulnerabilities discovered by Marcin “Icewall” Noga . Blog post authored by Marcin Noga and Jaeson Schultz . Update 2016-08-01: Talos has produced a video demonstrating how flaws in libarchive can be exploited using Splunk 6.4.1 as an attack vector. Release 3.2.1 of Libarchive addresses these issues, and Splunk has released patches .
libarchive is an open-source library that provides access to a variety of different file archive formats, and it’s used just about everywhere . Cisco Talos has recently worked with the maintainers of libarchive to patch three rather severe bugs in the library. Because of the number of products that include libarchive in their handling of compressed files, Talos urges all users to patch/upgrade related, vulnerable software.
## TALOS-
Talos
The Poisoned Archives
blogs_talos·2016-06-21·CVSS 7.8
[HIGH] The Poisoned Archives
Vulnerabilities discovered by Marcin “Icewall” Noga. Blog post authored by Marcin Noga and Jaeson Schultz.
Update 2016-08-01: Talos has produced a video demonstrating how flaws in libarchive can be exploited using Splunk 6.4.1 as an attack vector. Release 3.2.1 of Libarchive addresses these issues, and Splunk has released patches.
libarchive is an open-source library that provides access to a variety of different file archive formats, and it’s used just about everywhere. Cisco Talos has recently worked with the maintainers of libarchive to patch three rather severe bugs in the library. Because of the number of products that include libarchive in their handling of compressed files, Talos urges all users to patch/upgrade related, vulnerable software.
### TALOS-2016-0152 [CVE-2016-4300]:7-Z
Bugzilla
CVE-2016-4301 libarchive: Stack buffer overflow in the mtree parse_device
bugzilla·2016-06-21·CVSS 7.8
CVE-2016-4301 [HIGH] CVE-2016-4301 libarchive: Stack buffer overflow in the mtree parse_device
CVE-2016-4301 libarchive: Stack buffer overflow in the mtree parse_device
An exploitable stack based buffer overflow vulnerability exists in the mtree parse_device functionality of libarchive. A specially crafted mtree file can cause a buffer overflow resulting in memory corruption/code execution. An attacker can send a malformed file to trigger this vulnerability.
External references:
http://www.talosintel.com/reports/TALOS-2016-0153/
Upstream fix:
https://github.com/libarchive/libarchive/commit/a550daeecf6bc689ade371349892ea17b5b97c77
Discussion:
Contrary to the Talos advisory, the affected code was only introduced after
the release of v3.1.2. Thus no Red Hat packages are affected.
http://blog.talosintel.com/2016/06/the-poisoned-archives.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.securityfocus.com/bid/91328http://www.talosintel.com/reports/TALOS-2016-0153/https://bugzilla.redhat.com/show_bug.cgi?id=1348441https://github.com/libarchive/libarchive/commit/a550daeecf6bc689ade371349892ea17b5b97c77https://github.com/libarchive/libarchive/issues/715https://security.gentoo.org/glsa/201701-03http://blog.talosintel.com/2016/06/the-poisoned-archives.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.securityfocus.com/bid/91328http://www.talosintel.com/reports/TALOS-2016-0153/https://bugzilla.redhat.com/show_bug.cgi?id=1348441https://github.com/libarchive/libarchive/commit/a550daeecf6bc689ade371349892ea17b5b97c77https://github.com/libarchive/libarchive/issues/715https://security.gentoo.org/glsa/201701-03
2016-09-21
Published