CVE-2013-0211
MEDIUM severity · CVSS 5 · CWE-189
5CVSS MEDIUM
Summary
Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of service (crash) via unspecified vectors, which triggers an improper conversion between unsigned and signed types, leading to a buffer overflow.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impactNone
Integrity impactNone
Availability impact—
Exploit probability (EPSS)4%
AV:N/AC:L/Au:N/C:N/I:N/A:P
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101687.htmlAdvisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101700.htmlAdvisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101872.htmlAdvisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101876.htmlAdvisory
- http://lists.opensuse.org/opensuse-updates/2015-03/msg00065.htmlAdvisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:147Advisory
- http://www.securityfocus.com/bid/58926
- http://www.securitytracker.com/id/1035995Advisory