CVE-2016-6250: Integer Overflow
Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors related to verifying filename lengths when writing an ISO9660 archive, which trigger a buffer overflow.
Other sources
The ISO9660 writer is subject to integer overflows when verifying the filename size. This can lead to a crash when writing ISO9660 images with 2GB or 4GB filenames.
External references: https://github.com/libarchive/libarchive/files/295073/libarchiveOverflow.txt https://github.com/libarchive/libarchive/issues/711
Upstream fix: https://github.com/libarchive/libarchive/commit/3014e198
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6250?
The severity of CVE-2016-6250 is considered high due to its potential to cause application crashes and arbitrary code execution.
How do I fix CVE-2016-6250?
To fix CVE-2016-6250, upgrade libarchive to version 3.2.1 or later.
Which versions of libarchive are affected by CVE-2016-6250?
Versions of libarchive prior to 3.2.1, including all versions up to and including 3.2.0, are affected by CVE-2016-6250.
What types of attacks can CVE-2016-6250 enable?
CVE-2016-6250 can enable remote attackers to crash the application or execute arbitrary code through malformed ISO9660 archives.
Is CVE-2016-6250 specific to any operating systems?
CVE-2016-6250 affects libarchive across different operating systems, notably including Oracle Linux 7.