Heap-based buffer overflow in archivestringappendfromwcs() (archivestring.c) in libarchive-3.4.1dev allows remote attackers to cause a denial of service (out-of-bounds write in heap memory resulting into a crash) via a crafted archive file. NOTE: this only affects users who downloaded the development code from GitHub. Users of the product's official releases are unaffected.
libarchive. Multiple memory corruption issues existed in libarchive. These issues were addressed with improved input validation.