A flaw was found in libarchive.
A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a malic
What happened
A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS).
Does it affect you
Not enough information
No products recorded, so this cannot be matched against anything.
What to do
The vendor has not published remediation yet. We do not invent it.
Vendor's affected list
- rhel
- Exactly 6.0
Sources
A verdict here is derived from what you told us and what the vendor published. It is not an assessment of your environment. Why we never say you are safe.