The read_Header function in archive_read_support_format_7zip.c in libarchive 3.2.1 allows remote attackers to cause a denial of service (out-of-bounds read) via multiple EmptyStream attributes in a header in a 7zip archive.
| Software | From | Fixed in |
|---|---|---|
| libarchive / libarchive | 3.2.1 | 3.2.1.x |
| opensuse / leap | 42.2 | 42.2.x |