Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 477
Alerts This Week
Warning Icon 1 477

Ubuntu 16.04 LTS USN-2981-1 Moderate: libarchive DoS Issue

ubuntu
Calendar Grey May 17, 2016
Scroller Ubuntu
Attention: A security advisory has been issued regarding libarchive flaws impacting numerous Ubuntu releases, potentially leading to system crashes or denial-of-service scenarios.
libarchive could be made to crash or run programs if it opened a specially crafted file.

Summary

libarchive could be made to crash or run programs if it opened a specially

crafted file.

Software Description:

- libarchive: Library to read/write archive files

Details:

It was discovered that libarchive incorrectly handled certain entry-size

values in ZIP archives. A remote attacker could use this issue to cause

libarchive to crash, resulting in a denial of service, or possibly execute

arbitrary code. This issue only applied to Ubuntu 14.04 LTS, Ubuntu 15.10

and Ubuntu 16.04 LTS. (CVE-2016-1541)

It was discovered that libarchive incorrectly handled memory when

processing certain tar files. A remote attacker could use this issue to

cause libarchive to crash, resulting in a denial of service. (CVE number

pending)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
  libarchive13                    3.1.2-11ubuntu0.16.04.1

Ubuntu 15.10:
  libarchive13                    3.1.2-11ubuntu0.15.10.1

Ubuntu 14.04 LTS:
  libarchive13                    3.1.2-7ubuntu2.2

Ubuntu 12.04 LTS:
  libarchive12                    3.0.3-6ubuntu1.2

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2981-1

CVE-2016-1541

May 17, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.