First published: Thu Jun 16 2016(Updated: )
Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors related to verifying filename lengths when writing an ISO9660 archive, which trigger a buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libarchive | <3.2.1 | 3.2.1 |
Oracle Linux | =7 | |
libarchive | <=3.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-6250 is considered high due to its potential to cause application crashes and arbitrary code execution.
To fix CVE-2016-6250, upgrade libarchive to version 3.2.1 or later.
Versions of libarchive prior to 3.2.1, including all versions up to and including 3.2.0, are affected by CVE-2016-6250.
CVE-2016-6250 can enable remote attackers to crash the application or execute arbitrary code through malformed ISO9660 archives.
CVE-2016-6250 affects libarchive across different operating systems, notably including Oracle Linux 7.