Red Hat Bugzilla – Bug 1439703
CVE-2016-10209 libarchive: NULL pointer dereference in archive_wstring_append_from_mbs function
Last modified: 2017-04-06 08:16:14 EDT
The archive_wstring_append_from_mbs function in archive_string.c in libarchive allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive file. Upstream bug: https://github.com/libarchive/libarchive/issues/842 Upstream patch: https://github.com/libarchive/libarchive/commit/e8a9de5eaf3b79fc3d990d056343bb52c51c5ba4
Created libarchive tracking bugs for this issue: Affects: fedora-all [bug 1439705] Created libarchive3 tracking bugs for this issue: Affects: epel-6 [bug 1439704]