The ISO9660 writer is subject to integer overflows when verifying the filename size. This can lead to a crash when writing ISO9660 images with 2GB or 4GB filenames. External references: https://github.com/libarchive/libarchive/files/295073/libarchiveOverflow.txt https://github.com/libarchive/libarchive/issues/711 Upstream fix: https://github.com/libarchive/libarchive/commit/3014e198
Created libarchive tracking bugs for this issue: Affects: fedora-all [bug 1352776]
*** Bug 1358366 has been marked as a duplicate of this bug. ***
CVE request: http://seclists.org/oss-sec/2016/q3/114
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2016:1844 https://rhn.redhat.com/errata/RHSA-2016-1844.html