Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to execute arbitrary code via crafted entry-size values in a ZIP archive.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libarchive | Aug 30, 2017 | May 7, 2016 |
| Amazon_linux | — | Upgrade libarchive | Sep 27, 2016 | May 7, 2016 |
| Centos_linux | — | Upgrade bsdcpioUpgrade bsdtarUpgrade libarchive-develUpgrade libarchive | Sep 16, 2016 | May 7, 2016 |
| Debian | — | Upgrade libarchive | May 10, 2016 | May 7, 2016 |
| Freebsd | — | Upgrade libarchive | Dec 10, 2025 | May 9, 2016 |
| Gentoo Linux | — | Upgrade app-arch/libarchive. | Oct 30, 2017 | May 7, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade libarchive | Nov 30, 2017 | May 7, 2016 |
| Oracle Solaris | — | Upgrade library/libarchive to version 3.1.2-0.175.3.10.0.1.0 on Solaris 11.3 | May 29, 2017 | May 7, 2016 |
| Oracle_linux | — | Upgrade libarchive-develUpgrade bsdcpioUpgrade bsdtarUpgrade libarchive | Sep 12, 2016 | May 2, 2016 |
| Redhat_linux | — | Upgrade bsdcpioUpgrade libarchive-debuginfoUpgrade libarchiveUpgrade libarchive-develUpgrade bsdtar | Oct 21, 2016 | May 7, 2016 |
| Suse | — | Upgrade libarchive13Upgrade libarchive-develUpgrade bsdtar | Jun 1, 2016 | May 7, 2016 |
| Ubuntu | — | Upgrade libarchive13Upgrade libarchive12 | May 17, 2016 | May 7, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub