CVE-2016-5418: Input Validation
Insomnia Security (as part of a pre-arranged commercial engagement) reports:
A vulnerability in libarchive exists that allows an archive Entry with type 1 (hardlink), but has a non-zero data size to cause a file overwrite. This vulnerability can be leveraged in a way that has a significant security impact (this was not clear at first during initial research by upstream).
Other sources
The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive file.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5418?
CVE-2016-5418 is classified as a moderate severity vulnerability.
How do I fix CVE-2016-5418?
To fix CVE-2016-5418, upgrade libarchive to version 3.2.2 or later.
What are the potential impacts of CVE-2016-5418?
CVE-2016-5418 could allow remote attackers to write to arbitrary files on the system.
Which versions of libarchive are affected by CVE-2016-5418?
CVE-2016-5418 affects libarchive versions 3.2.0 and earlier.
Is CVE-2016-5418 relevant to Red Hat Enterprise Linux users?
Yes, CVE-2016-5418 specifically affects several Red Hat Enterprise Linux versions including 6.0 and 7.0.