First published: Sun Apr 30 2017(Updated: )
CVE-2016-10350 The archive_read_format_cab_read_header function in archive_read_support_format_cab.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file. CVE-2016-10349 The archive_le32dec function in archive_endian.h in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file. CVE-2016-10209 The archive_wstring_append_from_mbs function in archive_string.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/libarchive | <3.1.2-7ubuntu2.6 | 3.1.2-7ubuntu2.6 |
ubuntu/libarchive | <3.2.2-3.1 | 3.2.2-3.1 |
ubuntu/libarchive | <3.1.2-11ubuntu0.16.04.4 | 3.1.2-11ubuntu0.16.04.4 |
debian/libarchive | 3.4.3-2+deb11u1 3.6.2-1+deb12u1 3.7.4-1 | |
libarchive | =3.2.2 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=17.1.0<=17.1.1 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=16.1.0<=16.1.5 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=15.1.0<=15.1.10 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=8.2.0<=8.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10350 has a severity rating that indicates it can cause a denial of service due to a heap-based buffer over-read.
To fix CVE-2016-10350, you should upgrade to a patched version of libarchive such as 3.2.2-3.1 or later.
CVE-2016-10350 affects libarchive versions prior to 3.2.2-3.1 and various other specific versions across distributions.
CVE-2016-10350 enables remote attackers to crash the application by exploiting crafted files.
CVE-2016-10350 impacts F5 BIG-IP and BIG-IQ Centralized Management products across multiple versions.