Total vulnerabilities in the database
The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file.
Software | From | Fixed in |
---|---|---|
libarchive / libarchive | - | 3.1.901a.x |
novell / suse_linux_enterprise_server | 12.0-sp1 | 12.0-sp1.x |
novell / suse_linux_enterprise_desktop | 12.0-sp1 | 12.0-sp1.x |
novell / suse_linux_enterprise_software_development_kit | 12.0-sp1 | 12.0-sp1.x |
canonical / ubuntu_linux | 12.04 | 12.04.x |
canonical / ubuntu_linux | 16.04 | 16.04.x |
canonical / ubuntu_linux | 15.10 | 15.10.x |
canonical / ubuntu_linux | 14.04 | 14.04.x |