Lucene search

K
f5F5F5:K35263486
HistoryFeb 23, 2017 - 12:00 a.m.

K35263486 : libarchive vulnerability CVE-2016-8688

2017-02-2300:00:00
my.f5.com
30

6 Medium

AI Score

Confidence

High

0.009 Low

EPSS

Percentile

82.9%

Security Advisory Description

The mtree bidder in libarchive 3.2.1 does not keep track of line sizes when extending the read-ahead, which allows remote attackers to cause a denial of service (crash) via a crafted file, which triggers an invalid read in the (1) detect_form or (2) bid_entry function in libarchive/archive_read_support_format_mtree.c. (CVE-2016-8688)
Impact
For BIG-IP and VIPRION platforms that are configured to use Virtual Clustered Multiprocessing (vCMP), an authenticated administrator can upload a specially crafted ISO file and use the ISO file to create a vCMP guest virtual machine. A successful attack may cause the bsdtar to stop responding while creating the vCMP guest virtual machine.

6 Medium

AI Score

Confidence

High

0.009 Low

EPSS

Percentile

82.9%