CVE-2016-1541

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
07/05/2016
Last modified:
05/01/2018

Description

Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to execute arbitrary code via crafted entry-size values in a ZIP archive.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:* 3.1.901a (including)