Libarchive Malformed cpio Archive Crash

Discussion in 'News Aggregator' started by Packet Storm, 29 Apr 2015.

  1. Packet Storm

    Packet Storm Guest

    Using a crafted tar file bsdtar can perform an out-of-bounds memory read which will lead to a SEGFAULT. The issue exists when the executable skips data in the archive. The amount of data to skip is defined in byte offset [16-19]. If ASLR is disabled, the issue can lead to high CPU load, and potential CPU exhaustion in single-core hosts.

    Continue reading...
     

Share This Page

Loading...