vulnerability

Oracle Linux: CVE-2016-5418: ELSA-2016-1844: libarchive security update (IMPORTANT) (Multiple Advisories)

Severity
7
CVSS
(AV:N/AC:H/Au:S/C:C/I:C/A:C)
Published
2016-09-12
Added
2016-09-12
Modified
2024-12-18

Description

The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive file.
A flaw was found in the way libarchive handled hardlink archive entries of non-zero size. Combined with flaws in libarchive's file system sandboxing, this issue could cause an application using libarchive to overwrite arbitrary files with arbitrary data from the archive.

Solution(s)

oracle-linux-upgrade-bsdcpiooracle-linux-upgrade-bsdtaroracle-linux-upgrade-libarchiveoracle-linux-upgrade-libarchive-devel
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.