CVE-2013-0211

Published

Severity

CVSS v3:
N/A
CVSS v2:
5 MEDIUM

Description

Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of service (crash) via unspecified vectors, which triggers an improper conversion between unsigned and signed types, leading to a buffer overflow.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:x64:*:*n/a3.1.2 (including)*
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*n/an/a12.04
cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:*n/an/a14.10
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*n/an/a14.04
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*n/an/a13.1
cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*n/an/a13.2
cpe:2.3:o:fedoraproject:fedora:17:*:*:*:*:*:*:*n/an/a17
cpe:2.3:o:fedoraproject:fedora:18:*:*:*:*:*:*:*n/an/a18
cpe:2.3:o:freebsd:freebsd:9.3:*:*:*:*:*:*:*n/an/a9.3

External Links