libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip file.
| Software | From | Fixed in |
|---|---|---|
| redhat / enterprise_linux_desktop | 7.0 | 7.0.x |
| redhat / enterprise_linux_server_aus | 7.2 | 7.2.x |
| redhat / enterprise_linux_workstation | 7.0 | 7.0.x |
| redhat / enterprise_linux_server | 7.0 | 7.0.x |
| redhat / enterprise_linux_hpc_node | 7.0 | 7.0.x |
| redhat / enterprise_linux_server_eus | 7.2 | 7.2.x |
| redhat / enterprise_linux_hpc_node_eus | 7.2 | 7.2.x |
| libarchive / libarchive | - | 3.1.901a.x |
| redhat / enterprise_linux_hpc_node | 6.0 | 6.0.x |
| redhat / enterprise_linux_desktop | 6.0 | 6.0.x |
| redhat / enterprise_linux_server | 6.0 | 6.0.x |
| redhat / enterprise_linux_workstation | 6.0 | 6.0.x |
| oracle / linux | 6 | 6.x |
| oracle / linux | 7 | 7.x |