CVE-2016-5844
published 2016-09-21CVE-2016-5844: Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a crafted ISO file.
medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a crafted ISO file.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libarchive | < libarchive 3.2.1-1 (bookworm) | libarchive 3.2.1-1 (bookworm) |
| libarchive | libarchive | <= 3.2.0 | — |
| libarchive | libarchive | >= 0 < 3.2.1-1 | 3.2.1-1 |
| libarchive | libarchive | >= 0 < 3.2.1-1 | 3.2.1-1 |
| libarchive | libarchive | >= 0 < 3.2.1-1 | 3.2.1-1 |
| libarchive | libarchive | >= 0 < 3.2.1-1 | 3.2.1-1 |
| libarchive | libarchive | >= 0 < 3.1.2-7ubuntu2.3 | 3.1.2-7ubuntu2.3 |
| libarchive | libarchive | >= 0 < 3.1.2-11ubuntu0.16.04.2 | 3.1.2-11ubuntu0.16.04.2 |
| oracle | linux | — | — |
| oracle | linux | — | — |
| oracle | solaris | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM