Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:17611
HistoryMay 02, 2019 - 5:49 a.m.

Denial Of Service (DoS)

2019-05-0205:49:22
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.011 Low

EPSS

Percentile

84.4%

libarchive is vulnerable to denial of service (DoS) attacks. This is caused when a corrupted cpio archive has a ridiculously large size for a symlink. malloc() fails here when trying to allocate memory to contain the entire symlink which allows remote attackers to affect the availability of the application via a CPIO archive with a large symlink.