Candidate: CVE-2016-4301 PublicDate: 2016-09-21 14:25:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4301 http://blog.talosintel.com/2016/06/the-poisoned-archives.html http://www.talosintel.com/reports/TALOS-2016-0153/ https://github.com/libarchive/libarchive/pull/715 Description: Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a crafted mtree file. Ubuntu-Description: Notes: mdeslaur> introduced after 3.1.2 Bugs: Priority: medium Discovered-by: Marcin ‘Icewall’ Noga Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_libarchive: upstream: https://github.com/libarchive/libarchive/commit/a550daeecf6bc689ade371349892ea17b5b97c77 upstream_libarchive: needed precise_libarchive: not-affected trusty_libarchive: not-affected trusty/esm_libarchive: not-affected vivid/stable-phone-overlay_libarchive: DNE vivid/ubuntu-core_libarchive: DNE wily_libarchive: not-affected xenial_libarchive: not-affected (3.1.2-11ubuntu0.16.04.1) esm-infra/xenial_libarchive: not-affected (3.1.2-11ubuntu0.16.04.1) devel_libarchive: not-affected (3.2.1-1)