CVE-2017-14166: Medium severity Libarchive libarchive vulnerability
Last updated 25 August 2025
Other sources
libarchive 3.3.2 allows remote attackers to cause a denial of service (xmldata heap-based buffer over-read and application crash) via a crafted xar archive, related to the mishandling of empty strings in the atol8 function in archivereadsupportformatxar.c.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14166?
CVE-2017-14166 has a high severity due to its potential to cause denial of service by crashing the application.
What versions of libarchive are affected by CVE-2017-14166?
CVE-2017-14166 affects libarchive version 3.3.2 and prior versions that mishandle crafted xar archives.
How do I fix CVE-2017-14166?
To fix CVE-2017-14166, update libarchive to a version higher than 3.3.2, such as 3.4.3 or later.
What kind of attack does CVE-2017-14166 enable?
CVE-2017-14166 enables remote attackers to execute a denial of service attack through manipulated xar archives.
Is there a workaround for CVE-2017-14166?
There is no official workaround for CVE-2017-14166; updating to a patched version is the recommended solution.