ZeroHour

CVE-2016-7166

CVSS 3.0
5.5 medium
EPSS
2%p75
Published
()
Modified
Description

libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip file.

Vendors
redhatlibarchiveoracle
Products
enterprise linux desktop, enterprise linux hpc node, enterprise linux hpc node eus, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux workstation, libarchive, linux
Weakness
CWE-399
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.