4.3
CVSSv2

CVE-2016-5844

Published: 21/09/2016 Updated: 27/12/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Integer overflow in the ISO parser in libarchive prior to 3.2.1 allows remote malicious users to cause a denial of service (application crash) via a crafted ISO file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libarchive libarchive

redhat enterprise linux server 6.0

redhat enterprise linux workstation 6.0

redhat enterprise linux desktop 6.0

redhat enterprise linux hpc node 6.0

redhat enterprise linux server eus 7.2

redhat enterprise linux workstation 7.0

redhat enterprise linux hpc node 7.0

redhat enterprise linux server 7.0

redhat enterprise linux hpc node eus 7.2

redhat enterprise linux server aus 7.2

redhat enterprise linux desktop 7.0

oracle linux 7

oracle linux 6

oracle solaris 11.3

Vendor Advisories

libarchive could be made to crash or run programs if it opened a specially crafted file ...
A flaw was found in the way libarchive handled hardlink archive entries of non-zero size Combined with flaws in libarchive's file system sandboxing, this issue could cause an application using libarchive to overwrite arbitrary files with arbitrary data from the archive (CVE-2016-5418) Multiple out-of-bounds write flaws were found in libarchive S ...
Undefined behavior (signed integer overflow) was discovered in libarchive, in the ISO parser A crafted file could potentially cause denial of service ...