CVE-2017-14501: Medium severity Libarchive libarchive vulnerability
An out-of-bounds read flaw exists in parsefileinfo in archivereadsupportformatiso9660.c in libarchive 3.3.2 when extracting a specially crafted iso9660 iso file, related to archivereadformatiso9660readheader.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14501?
CVE-2017-14501 is classified as a high-severity vulnerability due to its potential to allow an attacker to exploit out-of-bounds read flaws.
How do I fix CVE-2017-14501?
To fix CVE-2017-14501, upgrade the libarchive package to versions 3.2.2-3.1ubuntu0.1 or later for Ubuntu or install the corresponding patched version for Debian.
What impact does CVE-2017-14501 have on systems?
CVE-2017-14501 can lead to information disclosure and could be exploited by an attacker to read parts of memory that should remain confidential.
Which versions of libarchive are affected by CVE-2017-14501?
Versions of libarchive prior to 3.3.2 are affected by CVE-2017-14501 if they are used in the context of handling specially crafted ISO9660 files.
Is my system vulnerable to CVE-2017-14501?
You may be vulnerable to CVE-2017-14501 if you are running affected versions of libarchive on your system without the appropriate patches.