Integer overflow in processing libarchive files in Oracle Linux - CVE-2016-5844

 

Integer overflow in processing libarchive files in Oracle Linux - CVE-2016-5844

Published: June 27, 2016 / Updated: January 10, 2017


Vulnerability identifier: #VU26
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5844
CWE-ID: CWE-732
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to boundary error when processing files in libarchive. A remote unauthenticated attacker can cause integer buffer overflow in choose_volume() by sending a specially crafted file to vulnerable server.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Affected software

Oracle Linux

libarchive (Alpine package)
IBM Tivoli Storage Manager

How to mitigate CVE-2016-5844

The vendor has issued a fix (3.2.1).

libarchive (Alpine package) - update to 3.1.2-r4

External References

Related Security Bulletins