ZeroHour

CVE-2016-4300

PoC ×2
CVSS 3.0
7.8 high
EPSS
5%p92
Published
()
Modified
Description

Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a 7zip file with a large number of substreams, which triggers a heap-based buffer overflow.

Vendors
libarchiveredhat
Products
libarchive, enterprise linux desktop, enterprise linux hpc node, enterprise linux hpc node eus, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux workstation
Weakness
CWE-190
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news