libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip file.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libarchive | Sep 20, 2017 | Sep 21, 2016 |
| Amazon_linux | — | Upgrade libarchive | Sep 27, 2016 | Sep 21, 2016 |
| Centos_linux | — | Upgrade libarchive-develUpgrade bsdcpioUpgrade libarchiveUpgrade bsdtar | Jul 1, 2017 | Sep 16, 2016 |
| Debian | — | Upgrade libarchive | Sep 25, 2016 | Sep 21, 2016 |
| Gentoo Linux | — | Upgrade app-arch/libarchive. | Oct 30, 2017 | Sep 21, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade libarchive | Nov 30, 2017 | Sep 21, 2016 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Sep 21, 2016 |
| Oracle_linux | — | Upgrade bsdcpioUpgrade libarchiveUpgrade bsdtarUpgrade libarchive-devel | Jul 1, 2017 | Feb 22, 2016 |
| Redhat_linux | — | Upgrade bsdcpioUpgrade bsdtarUpgrade libarchive-develUpgrade libarchive-debuginfoUpgrade libarchive | Oct 21, 2016 | Sep 12, 2016 |
| Ubuntu | — | Upgrade libarchive13Upgrade libarchive12 | Mar 10, 2017 | Sep 21, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub