CVE-2016-7166
published 2016-09-21CVE-2016-7166: libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption…
PriorityP417medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.64%
73.8th percentile
libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip file.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libarchive | < libarchive 3.2.0-2 (bookworm) | libarchive 3.2.0-2 (bookworm) |
| libarchive | libarchive | <= 3.1.901a | — |
| libarchive | libarchive | >= 0 < 3.2.0-2 | 3.2.0-2 |
| libarchive | libarchive | >= 0 < 3.2.0-2 | 3.2.0-2 |
| libarchive | libarchive | >= 0 < 3.2.0-2 | 3.2.0-2 |
| libarchive | libarchive | >= 0 < 3.2.0-2 | 3.2.0-2 |
| libarchive | libarchive | >= 0 < 3.1.2-7ubuntu2.4 | 3.1.2-7ubuntu2.4 |
| libarchive | libarchive | >= 0 < 3.1.2-11ubuntu0.16.04.3 | 3.1.2-11ubuntu0.16.04.3 |
| oracle | linux | — | — |
| oracle | linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8hwj-j49v-pfwp: libarchive before 3
ghsa_unreviewed·2022-05-13
CVE-2016-7166 [MEDIUM] GHSA-8hwj-j49v-pfwp: libarchive before 3
libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip file.
OSV
libarchive vulnerabilities
osv·2017-03-09·CVSS 7.5
CVE-2016-5418 [HIGH] libarchive vulnerabilities
libarchive vulnerabilities
It was discovered that libarchive incorrectly handled hardlink entries when
extracting archives. A remote attacker could possibly use this issue to
overwrite arbitrary files. (CVE-2016-5418)
Christian Wressnegger, Alwin Maier, and Fabian Yamaguchi discovered that
libarchive incorrectly handled filename lengths when writing ISO9660
archives. A remote attacker could use this issue to cause libarchive to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only applied to Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and
Ubuntu 16.04 LTS. (CVE-2016-6250)
Alexander Cherepanov discovered that libarchive incorrectly handled
recursive decompressions. A remote attacker could possibly use this issue
to cause libarchive to hang, resulting in a de
OSV
CVE-2016-7166: libarchive before 3
osv·2016-09-21·CVSS 5.5
CVE-2016-7166 [MEDIUM] CVE-2016-7166: libarchive before 3
libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip file.
Ubuntu
libarchive vulnerabilities
vendor_ubuntu·2017-03-09·CVSS 7.5
CVE-2016-5418 [HIGH] libarchive vulnerabilities
Title: libarchive vulnerabilities
Summary: libarchive could be made to crash, overwrite files, or run programs as your
login if it opened a specially crafted file.
It was discovered that libarchive incorrectly handled hardlink entries when
extracting archives. A remote attacker could possibly use this issue to
overwrite arbitrary files. (CVE-2016-5418)
Christian Wressnegger, Alwin Maier, and Fabian Yamaguchi discovered that
libarchive incorrectly handled filename lengths when writing ISO9660
archives. A remote attacker could use this issue to cause libarchive to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only applied to Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and
Ubuntu 16.04 LTS. (CVE-2016-6250)
Alexander Cherepanov discovered that libarchive in
Red Hat
libarchive: Denial of service using a crafted gzip file
vendor_redhat·2016-02-22·CVSS 5.5
CVE-2016-7166 [MEDIUM] CWE-770 libarchive: Denial of service using a crafted gzip file
libarchive: Denial of service using a crafted gzip file
libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip file.
A vulnerability was found in libarchive. A specially crafted gzip file can cause libarchive to allocate memory without limit, eventually leading to a crash.
Debian
CVE-2016-7166: libarchive - libarchive before 3.2.0 does not limit the number of recursive decompressions, w...
vendor_debian·2016·CVSS 5.5
CVE-2016-7166 [MEDIUM] CVE-2016-7166: libarchive - libarchive before 3.2.0 does not limit the number of recursive decompressions, w...
libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip file.
Scope: local
bookworm: resolved (fixed in 3.2.0-2)
bullseye: resolved (fixed in 3.2.0-2)
forky: resolved (fixed in 3.2.0-2)
sid: resolved (fixed in 3.2.0-2)
trixie: resolved (fixed in 3.2.0-2)
No detection rules found.
Bugzilla
CVE-2015-8920 CVE-2015-8921 CVE-2015-8932 CVE-2015-8933 CVE-2016-4809 CVE-2016-5844 CVE-2016-7166 libarchive: various flaws [epel-5]
bugzilla·2016-07-05·CVSS 5.5
CVE-2015-8920 [MEDIUM] CVE-2015-8920 CVE-2015-8921 CVE-2015-8932 CVE-2015-8933 CVE-2016-4809 CVE-2016-5844 CVE-2016-7166 libarchive: various flaws [epel-5]
CVE-2015-8920 CVE-2015-8921 CVE-2015-8932 CVE-2015-8933 CVE-2016-4809 CVE-2016-5844 CVE-2016-7166 libarchive: various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messag
Bugzilla
CVE-2016-7166 libarchive: Denial of service using a crafted gzip file
bugzilla·2016-06-16·CVSS 5.5
CVE-2016-7166 [MEDIUM] CVE-2016-7166 libarchive: Denial of service using a crafted gzip file
CVE-2016-7166 libarchive: Denial of service using a crafted gzip file
A specially crafted gzip file can cause libarchive to allocate memory
without limit, eventually leading to a crash.
External references:
https://github.com/libarchive/libarchive/issues/660
Upstream fix:
https://github.com/libarchive/libarchive/commit/6e06b1c89
Discussion:
Created libarchive tracking bugs for this issue:
Affects: epel-5 [bug 1352775]
Affects: fedora-all [bug 1352776]
---
FTR: Not back-porting follow-up patch 37649d274867edd2dd25d8a3057c3b6cd81ce83e
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1850 https://rhn.redhat.com/errata/RHSA-2016-1850.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
http://rhn.redhat.com/errata/RHSA-2016-1844.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1850.htmlhttp://www.openwall.com/lists/oss-security/2016/09/08/15http://www.openwall.com/lists/oss-security/2016/09/08/18http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.securityfocus.com/bid/92901https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=207362https://bugzilla.redhat.com/show_bug.cgi?id=1347086https://github.com/libarchive/libarchive/commit/6e06b1c89dd0d16f74894eac4cfc1327a06ee4a0https://github.com/libarchive/libarchive/issues/660https://security.gentoo.org/glsa/201701-03http://rhn.redhat.com/errata/RHSA-2016-1844.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1850.htmlhttp://www.openwall.com/lists/oss-security/2016/09/08/15http://www.openwall.com/lists/oss-security/2016/09/08/18http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.securityfocus.com/bid/92901https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=207362https://bugzilla.redhat.com/show_bug.cgi?id=1347086https://github.com/libarchive/libarchive/commit/6e06b1c89dd0d16f74894eac4cfc1327a06ee4a0https://github.com/libarchive/libarchive/issues/660https://security.gentoo.org/glsa/201701-03
2016-09-21
Published