ZeroHour

CVE-2016-4302

PoC ×2
CVSS 3.0
7.8 high
EPSS
5%p91
Published
()
Modified
Description

Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a RAR file with a zero-sized dictionary.

Vendors
redhatlibarchive
Products
enterprise linux desktop, enterprise linux hpc node, enterprise linux hpc node eus, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux workstation, libarchive
Weakness
CWE-119
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news