The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Enterprise_linux_desktop | Redhat | 6.0 (including) | 6.0 (including) |
Enterprise_linux_hpc_node | Redhat | 6.0 (including) | 6.0 (including) |
Enterprise_linux_server | Redhat | 6.0 (including) | 6.0 (including) |
Enterprise_linux_workstation | Redhat | 6.0 (including) | 6.0 (including) |
Red Hat Enterprise Linux 6 | RedHat | libarchive-0:2.8.3-7.el6_8 | * |
Red Hat Enterprise Linux 7 | RedHat | libarchive-0:3.1.2-10.el7_2 | * |
Red Hat OpenShift Container Platform 3.2 | RedHat | atomic-openshift-0:3.2.1.15-1.git.0.d84be7f.el7 | * |
Red Hat OpenShift Container Platform 3.2 | RedHat | heapster-0:1.1.0-1.beta2.el7.1 | * |
Red Hat OpenShift Container Platform 3.2 | RedHat | openshift-ansible-0:3.2.28-1.git.0.5a85fc5.el7 | * |
Red Hat OpenShift Enterprise 3.1 | RedHat | atomic-openshift-0:3.1.1.7-1.git.0.65f396b.el7aos | * |
Libarchive | Ubuntu | precise | * |
Libarchive | Ubuntu | trusty | * |
Libarchive | Ubuntu | upstream | * |
Libarchive | Ubuntu | xenial | * |
Libarchive | Ubuntu | yakkety | * |