First published: Fri Apr 13 2012(Updated: )
Multiple use-after-free vulnerabilities in libarchive 2.8.4 and 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted (1) TAR archive or (2) ISO9660 image.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD libarchive | =2.8.5 | |
FreeBSD libarchive | =2.8.4 | |
libarchive | =2.8.4 | |
libarchive | =2.8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1779 has a moderate severity level due to its potential for causing application crashes and denial of service.
To fix CVE-2011-1779, you should upgrade libarchive to versions 2.8.6 or later, which contain the necessary patches.
CVE-2011-1779 can lead to denial of service due to application crashes when handling crafted TAR archives or ISO9660 images.
CVE-2011-1779 affects libarchive versions 2.8.4 and 2.8.5.
Yes, attackers can exploit CVE-2011-1779 remotely by sending specially crafted TAR or ISO9660 files.