FreeBSD Security Advisory - FreeBSD-SA-16:23.libarchive

Discussion in 'News Aggregator' started by Packet Storm, 2 Jun 2016.

  1. Packet Storm

    Packet Storm Guest

    FreeBSD Security Advisory - An integer signedness error in the archive_write_zip_data() function in archive_write_set_format_zip.c in libarchive(2) could lead to a buffer overflow on 64-bit machines. An attacker who can provide input of their choice for creating a ZIP archive can cause a buffer overflow in libarchive(2) that results in a core dump or possibly execution of arbitrary code provided by the attacker.

    Continue reading...
     

Share This Page

Loading...