F5-K000148259: Null Pointer Dereference
CVE-2016-10350 The archivereadformatcabreadheader function in archivereadsupportformatcab.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file. CVE-2016-10349 The archivele32dec function in archiveendian.h in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000148259?
The severity of F5-K000148259 is classified as critical due to its potential for denial of service attacks.
How do I fix F5-K000148259?
To fix F5-K000148259, upgrade the affected F5 BIG-IP or BIG-IQ versions to the latest available release that addresses this vulnerability.
Which products are affected by F5-K000148259?
The products affected by F5-K000148259 include specific versions of F5 BIG-IP and F5 BIG-IQ Centralized Management.
What type of attack does F5-K000148259 pertain to?
F5-K000148259 pertains to a denial of service attack that can cause heap-based buffer over-read and application crash.
Is there a workaround for F5-K000148259 until a patch is applied?
There are no specific workarounds for F5-K000148259, and it is strongly recommended to apply the patch as soon as possible.