CVE-2013-0211
Publication date 25 March 2013
Last updated 24 July 2024
Ubuntu priority
Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of service (crash) via unspecified vectors, which triggers an improper conversion between unsigned and signed types, leading to a buffer overflow.
Status
Package | Ubuntu Release | Status |
---|---|---|
libarchive | ||
14.04 LTS trusty |
Not affected
|
|
References
Related Ubuntu Security Notices (USN)
- USN-2549-1
- libarchive vulnerabilities
- 25 March 2015