CVE-2016-2347: Integer Overflow
Published Apr 21, 2017
·Updated
Integer underflow in the decodelevel3header function in lib/lhafileheader.c in Lhasa before 0.3.1 allows remote attackers to execute arbitrary code via a crafted archive.
Affected Software
5 affected components
openSUSE Leap=42.1
openSUSE openSUSE=13.2
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Lhasa Project Lhasa<=0.3.0
Remediation
Patch Available
Event History
Apr 21, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2347?
CVE-2016-2347 has a high severity rating allowing remote attackers to potentially execute arbitrary code.
2
How do I fix CVE-2016-2347?
To fix CVE-2016-2347, update to a version of Lhasa greater than 0.3.0 or apply the available security patches for your operating system.
3
Which software is affected by CVE-2016-2347?
CVE-2016-2347 affects Lhasa versions prior to 0.3.1 and specific versions of openSUSE and Debian Linux.
4
What type of vulnerability is CVE-2016-2347?
CVE-2016-2347 is categorized as an integer underflow vulnerability that impacts the decode_level3_header function.
5
Is CVE-2016-2347 remotely exploitable?
Yes, CVE-2016-2347 can be exploited remotely through crafted archive files.