USN-8902-1: libarchive vulnerability
Ubuntu patches libarchive signed integer overflow in ZIP writer that could let crafted encrypted entries crash the library or execute arbitrary code.
USN-8902-1 fixes a libarchive vulnerability where a signed integer overflow occurs in the ZIP writer when handling encrypted entries with sizes near the maximum value. An attacker could use the flaw to cause libarchive to crash or execute arbitrary code. Ubuntu has released updated packages addressing the issue.
- Signed integer overflow in libarchive ZIP writer handling encrypted entries near maximum size
- Crafted input could cause crash or arbitrary code execution
- Fix shipped as Ubuntu Security Notice USN-8902-1
It was discovered that libarchive had a signed integer overflow in its ZIP writer when handling encrypted entries with sizes near the maximum value. An attacker could possibly use this issue to cause libarchive to crash or execute arbitrary code.
This source does not provide full text. Read it at ubuntu.com.