The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive file.
| Software | From | Fixed in |
|---|---|---|
| redhat / enterprise_linux_hpc_node | 6.0 | 6.0.x |
| redhat / enterprise_linux_desktop | 6.0 | 6.0.x |
| redhat / enterprise_linux_server | 6.0 | 6.0.x |
| redhat / enterprise_linux_workstation | 6.0 | 6.0.x |
| oracle / linux | 6 | 6.x |
| oracle / linux | 7 | 7.x |
| redhat / openshift | 3.1 | 3.1.x |
| redhat / openshift | 3.2 | 3.2.x |
| libarchive / libarchive | - | 3.2.0.x |
| redhat / enterprise_linux_desktop | 7.0 | 7.0.x |
| redhat / enterprise_linux_server_aus | 7.2 | 7.2.x |
| redhat / enterprise_linux_workstation | 7.0 | 7.0.x |
| redhat / enterprise_linux_server | 7.0 | 7.0.x |
| redhat / enterprise_linux_hpc_node | 7.0 | 7.0.x |
| redhat / enterprise_linux_server_eus | 7.2 | 7.2.x |
| redhat / enterprise_linux_hpc_node_eus | 7.2 | 7.2.x |