CVE-2016-1541

HIGH8.8EPSS 12.3%

libarchive - security update

Published: 5/7/2016Modified: 11/19/2025
Also known as:DSA-3574-1ALPINE-CVE-2016-1541DEBIAN-CVE-2016-1541

Description

Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to execute arbitrary code via crafted entry-size values in a ZIP archive.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.8CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References (2)