Vulnerability Name: | CVE-2010-4666 (CCN-74881) | ||||||||
Assigned: | 2011-01-03 | ||||||||
Published: | 2012-03-24 | ||||||||
Updated: | 2012-04-16 | ||||||||
Summary: | Buffer overflow in libarchive 3.0 pre-release code allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CAB file, which is not properly handled during the reading of Huffman code data within LZX compressed data. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-119 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: libarchive Web site libarchive Source: CONFIRM Type: UNKNOWN http://code.google.com/p/libarchive/source/detail?r=2842 Source: MITRE Type: CNA CVE-2010-4666 Source: CCN Type: OSVDB ID: 77467 libarchive LZX Huffman Code CAB File Handling Remote Overflow Source: CCN Type: Red Hat Bugzilla Bug 705849 CVE-2010-4666 CVE-2011-1777 CVE-2011-1778 CVE-2011-1779 Libarchive multiple security issues Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=705849 Source: XF Type: UNKNOWN libarchive-cab-bo(74881) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |