#VU15818 Out-of-bounds read in libarchive - CVE-2017-14501
Published: November 12, 2018 / Updated: November 13, 2018
libarchive
libarchive
Description
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to out-of-bounds read condition in the parse_file_info function, as defined in the archive_read_support_format_iso9660.c source code file when extracting ISO 9660 files. A remote attacker can trick the victim into extracting an ISO 9660 file that submits malicious input and cause the service to crash.