CVE-2016-10349: Buffer Overflow
CVE-2016-10350 The archivereadformatcabreadheader function in archivereadsupportformatcab.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file. CVE-2016-10349 The archivele32dec function in archiveendian.h in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10349?
CVE-2016-10349 has a severity rating that indicates it may lead to a denial of service through heap-based buffer over-read and application crash.
How do I fix CVE-2016-10349?
To fix CVE-2016-10349, update the libarchive package to version 3.2.2-3.1 or later for affected systems.
What systems are affected by CVE-2016-10349?
CVE-2016-10349 affects various versions of the libarchive library across Ubuntu and Debian distributions, as well as F5 BIG-IP products.
Is CVE-2016-10349 a remote code execution vulnerability?
No, CVE-2016-10349 is primarily a denial of service vulnerability and does not allow for remote code execution.
What should I do if my system is vulnerable to CVE-2016-10349?
If your system is vulnerable to CVE-2016-10349, it is recommended to apply the necessary updates as soon as possible to mitigate the risk.