|
|
|
Vulnerability Note VU#970849libarchive does not properly terminate loopOverviewlibarchive contains a vulnerability that may allow an attacker to cause a denial of service.I. DescriptionThe libarchive library provides an interface for reading and writing archive files.There is a vulnerability in libarchive that occurs when it parses the pax interchange format. If an archive prematurely ends within a pax extension, libarchive may enter an infinite loop.
Multiple operating system vendors have released an update to address this issue. Administrators should the systems affected portion of this document for more information.
References
Theanks to CERT-FI and CPNI for information that was used in this report. This document was written by Ryan Giobbi.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||||||||