PublicDateAtUSN: 2016-09-21 Candidate: CVE-2016-7166 PublicDate: 2016-09-21 14:25:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7166 https://ubuntu.com/security/notices/USN-3225-1 Description: libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip file. Ubuntu-Description: Notes: Bugs: https://github.com/libarchive/libarchive/issues/660 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=207362 Priority: medium Discovered-by: Alexander Cherepanov Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_libarchive: upstream: https://github.com/libarchive/libarchive/commit/6e06b1c89dd0d16f74894eac4cfc1327a06ee4a0 upstream: https://github.com/libarchive/libarchive/commit/37649d274867edd2dd25d8a3057c3b6cd81ce83e (not needed) upstream_libarchive: released (3.2.0-2) precise_libarchive: released (3.0.3-6ubuntu1.4) trusty_libarchive: released (3.1.2-7ubuntu2.4) trusty/esm_libarchive: released (3.1.2-7ubuntu2.4) vivid/stable-phone-overlay_libarchive: DNE vivid/ubuntu-core_libarchive: DNE xenial_libarchive: released (3.1.2-11ubuntu0.16.04.3) esm-infra/xenial_libarchive: released (3.1.2-11ubuntu0.16.04.3) yakkety_libarchive: not-affected (3.2.1-2) devel_libarchive: not-affected (3.2.1-2)