Lucene search

K
f5F5F5:K13074505
HistoryFeb 23, 2017 - 12:00 a.m.

K13074505 : libarchive vulnerability CVE-2016-8687

2017-02-2300:00:00
my.f5.com
24

6.8 Medium

AI Score

Confidence

High

0.019 Low

EPSS

Percentile

88.5%

Security Advisory Description

Stack-based buffer overflow in the safe_fprintf function in tar/util.c in libarchive 3.2.1 allows remote attackers to cause a denial of service via a crafted non-printable multibyte character in a filename. (CVE-2016-8687)
Impact
For BIG-IP and VIPRION platforms that are configured to use Virtual Clustered Multiprocessing (vCMP), an authenticated administrator can upload a specially crafted ISO file and use the ISO file to create a vCMP guest virtual machine. A successful attack may cause the bsdtar to stop responding while creating the vCMP guest virtual machine.
This functionality is exposed only to authenticated administrators using the LineRate Manager GUI, CLI, or REST API when performing a system restore with a backup file of the LineRate system that has been tampered with. A successful attack may allow unauthorized modification of files.