Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a crafted mtree file.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libarchive | Jul 30, 2024 | Sep 21, 2016 |
| Freebsd | — | Upgrade libarchive | Dec 10, 2025 | Jun 23, 2016 |
| Gentoo Linux | — | Upgrade app-arch/libarchive. | Oct 30, 2017 | Sep 21, 2016 |
| Oracle Solaris | — | Upgrade library/libarchive to version 3.2.1-0.175.3.11.0.1.0 on Solaris 11.3 | May 29, 2017 | Sep 21, 2016 |
| Suse | — | Upgrade bsdtarUpgrade libarchive-develUpgrade libarchive13 | Jul 29, 2016 | Jul 29, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub