CVE-2016-6250
published 2016-09-21CVE-2016-6250: Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary…
PriorityP347high8.6CVSS 3.0
AVNACLPRNUINSUCLILAH
EPSS
6.25%
92.8th percentile
Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors related to verifying filename lengths when writing an ISO9660 archive, which trigger a buffer overflow.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libarchive | < libarchive 3.2.1-1 (bookworm) | libarchive 3.2.1-1 (bookworm) |
| libarchive | libarchive | <= 3.2.0 | — |
| libarchive | libarchive | >= 0 < 3.2.1-1 | 3.2.1-1 |
| libarchive | libarchive | >= 0 < 3.2.1-1 | 3.2.1-1 |
| libarchive | libarchive | >= 0 < 3.2.1-1 | 3.2.1-1 |
| libarchive | libarchive | >= 0 < 3.2.1-1 | 3.2.1-1 |
| libarchive | libarchive | >= 0 < 3.1.2-7ubuntu2.4 | 3.1.2-7ubuntu2.4 |
| libarchive | libarchive | >= 0 < 3.1.2-11ubuntu0.16.04.3 | 3.1.2-11ubuntu0.16.04.3 |
| oracle | linux | — | — |
CVSS provenance
nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv8.6HIGH
vendor_debian8.6LOW
vendor_redhat8.6HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m79p-4p7w-x53w: Integer overflow in the ISO9660 writer in libarchive before 3
ghsa_unreviewed·2022-05-13
CVE-2016-6250 [HIGH] CWE-190 GHSA-m79p-4p7w-x53w: Integer overflow in the ISO9660 writer in libarchive before 3
Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors related to verifying filename lengths when writing an ISO9660 archive, which trigger a buffer overflow.
OSV
libarchive vulnerabilities
osv·2017-03-09·CVSS 7.5
CVE-2016-5418 [HIGH] libarchive vulnerabilities
libarchive vulnerabilities
It was discovered that libarchive incorrectly handled hardlink entries when
extracting archives. A remote attacker could possibly use this issue to
overwrite arbitrary files. (CVE-2016-5418)
Christian Wressnegger, Alwin Maier, and Fabian Yamaguchi discovered that
libarchive incorrectly handled filename lengths when writing ISO9660
archives. A remote attacker could use this issue to cause libarchive to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only applied to Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and
Ubuntu 16.04 LTS. (CVE-2016-6250)
Alexander Cherepanov discovered that libarchive incorrectly handled
recursive decompressions. A remote attacker could possibly use this issue
to cause libarchive to hang, resulting in a de
OSV
CVE-2016-6250: Integer overflow in the ISO9660 writer in libarchive before 3
osv·2016-09-21·CVSS 8.6
CVE-2016-6250 [HIGH] CVE-2016-6250: Integer overflow in the ISO9660 writer in libarchive before 3
Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors related to verifying filename lengths when writing an ISO9660 archive, which trigger a buffer overflow.
Ubuntu
libarchive vulnerabilities
vendor_ubuntu·2017-03-09·CVSS 7.5
CVE-2016-5418 [HIGH] libarchive vulnerabilities
Title: libarchive vulnerabilities
Summary: libarchive could be made to crash, overwrite files, or run programs as your
login if it opened a specially crafted file.
It was discovered that libarchive incorrectly handled hardlink entries when
extracting archives. A remote attacker could possibly use this issue to
overwrite arbitrary files. (CVE-2016-5418)
Christian Wressnegger, Alwin Maier, and Fabian Yamaguchi discovered that
libarchive incorrectly handled filename lengths when writing ISO9660
archives. A remote attacker could use this issue to cause libarchive to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only applied to Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and
Ubuntu 16.04 LTS. (CVE-2016-6250)
Alexander Cherepanov discovered that libarchive in
Red Hat
libarchive: Buffer overflow when writing large iso9660 containers
vendor_redhat·2016-05-29·CVSS 8.6
CVE-2016-6250 [HIGH] CWE-190 libarchive: Buffer overflow when writing large iso9660 containers
libarchive: Buffer overflow when writing large iso9660 containers
Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors related to verifying filename lengths when writing an ISO9660 archive, which trigger a buffer overflow.
A vulnerability was found in libarchive. An attempt to create an ISO9660 volume with 2GB or 4GB filenames could cause the application to crash.
Package: libarchive (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2016-6250: libarchive - Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote ...
vendor_debian·2016·CVSS 8.6
CVE-2016-6250 [HIGH] CVE-2016-6250: libarchive - Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote ...
Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors related to verifying filename lengths when writing an ISO9660 archive, which trigger a buffer overflow.
Scope: local
bookworm: resolved (fixed in 3.2.1-1)
bullseye: resolved (fixed in 3.2.1-1)
forky: resolved (fixed in 3.2.1-1)
sid: resolved (fixed in 3.2.1-1)
trixie: resolved (fixed in 3.2.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-6250 libarchive3: libarchive: Integer overflow when verifying filename size [epel-6]
bugzilla·2016-07-20·CVSS 8.6
CVE-2016-6250 [HIGH] CVE-2016-6250 libarchive3: libarchive: Integer overflow when verifying filename size [epel-6]
CVE-2016-6250 libarchive3: libarchive: Integer overflow when verifying filename size [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-
Bugzilla
CVE-2016-6250 mingw-libarchive: libarchive: Integer overflow when verifying filename size [fedora-all]
bugzilla·2016-07-20·CVSS 8.6
CVE-2016-6250 [HIGH] CVE-2016-6250 mingw-libarchive: libarchive: Integer overflow when verifying filename size [fedora-all]
CVE-2016-6250 mingw-libarchive: libarchive: Integer overflow when verifying filename size [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
Bugzilla
CVE-2016-6250 libarchive: Integer overflow when verifying filename size [fedora-all]
bugzilla·2016-07-20·CVSS 8.6
CVE-2016-6250 [HIGH] CVE-2016-6250 libarchive: Integer overflow when verifying filename size [fedora-all]
CVE-2016-6250 libarchive: Integer overflow when verifying filename size [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versi
Bugzilla
CVE-2016-6250 libarchive: Integer overflow when verifying filename size [epel-5]
bugzilla·2016-07-20·CVSS 8.6
CVE-2016-6250 [HIGH] CVE-2016-6250 libarchive: Integer overflow when verifying filename size [epel-5]
CVE-2016-6250 libarchive: Integer overflow when verifying filename size [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-bugs
Bugzilla
CVE-2016-6250 libarchive: Buffer overflow when writing large iso9660 containers
bugzilla·2016-06-16·CVSS 8.6
CVE-2016-6250 [HIGH] CVE-2016-6250 libarchive: Buffer overflow when writing large iso9660 containers
CVE-2016-6250 libarchive: Buffer overflow when writing large iso9660 containers
The ISO9660 writer is subject to integer overflows when verifying the
filename size. This can lead to a crash when writing ISO9660 images with
2GB or 4GB filenames.
External references:
https://github.com/libarchive/libarchive/files/295073/libarchiveOverflow.txt https://github.com/libarchive/libarchive/issues/711
Upstream fix:
https://github.com/libarchive/libarchive/commit/3014e198
Discussion:
Created libarchive tracking bugs for this issue:
Affects: fedora-all [bug 1352776]
---
*** Bug 1358366 has been marked as a duplicate of this bug. ***
---
CVE request:
http://seclists.org/oss-sec/2016/q3/114
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-20
http://rhn.redhat.com/errata/RHSA-2016-1844.htmlhttp://www.openwall.com/lists/oss-security/2016/07/20/1http://www.openwall.com/lists/oss-security/2016/07/21/3http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.securityfocus.com/bid/92036http://www.securitytracker.com/id/1036431https://bugzilla.redhat.com/show_bug.cgi?id=1347085https://github.com/libarchive/libarchive/commit/3014e198https://github.com/libarchive/libarchive/files/295073/libarchiveOverflow.txthttps://github.com/libarchive/libarchive/issues/711https://security.gentoo.org/glsa/201701-03http://rhn.redhat.com/errata/RHSA-2016-1844.htmlhttp://www.openwall.com/lists/oss-security/2016/07/20/1http://www.openwall.com/lists/oss-security/2016/07/21/3http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.securityfocus.com/bid/92036http://www.securitytracker.com/id/1036431https://bugzilla.redhat.com/show_bug.cgi?id=1347085https://github.com/libarchive/libarchive/commit/3014e198https://github.com/libarchive/libarchive/files/295073/libarchiveOverflow.txthttps://github.com/libarchive/libarchive/issues/711https://security.gentoo.org/glsa/201701-03
2016-09-21
Published