You are here

CVE-2013-0211

Vincent (CVE) Danen's picture
Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of service (crash) via unspecified vectors, which triggers an improper conversion between unsigned and signed types, leading to a buffer overflow.

Details Source

Mitre

Statement

This issue affects the version of libarchive as shipped with Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this issue as having low
security impact, a future update may address this flaw.

Public Date

2013-03-25 00:00:00

Impact

Low

Bugzilla

CVE-2013-0211 libarchive: read buffer overflow on 64-bit systems

Bugzilla ID

902 998

CVSS Status

draft

Base Score

2.10

Base Metrics

AV:L/AC:L/Au:N/C:N/I:N/A:P

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 6 libarchive Fix deferred