libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Enterprise_linux_desktop | Redhat | 7.0 (including) | 7.0 (including) |
Enterprise_linux_hpc_node | Redhat | 7.0 (including) | 7.0 (including) |
Enterprise_linux_hpc_node_eus | Redhat | 7.2 (including) | 7.2 (including) |
Enterprise_linux_server | Redhat | 7.0 (including) | 7.0 (including) |
Enterprise_linux_server_aus | Redhat | 7.2 (including) | 7.2 (including) |
Enterprise_linux_server_eus | Redhat | 7.2 (including) | 7.2 (including) |
Enterprise_linux_workstation | Redhat | 7.0 (including) | 7.0 (including) |
Libarchive | Ubuntu | precise | * |
Libarchive | Ubuntu | trusty | * |
Libarchive | Ubuntu | upstream | * |
Libarchive | Ubuntu | xenial | * |
Red Hat Enterprise Linux 6 | RedHat | libarchive-0:2.8.3-7.el6_8 | * |
Red Hat Enterprise Linux 7 | RedHat | libarchive-0:3.1.2-10.el7_2 | * |