Your submission was sent successfully! Close

CVE-2017-13813

Published: 13 November 2017

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "libarchive" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted archive file.

Priority

Medium

CVSS 3 base score: 7.8

Status

Package Release Status
libarchive
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 16.04 ESM (Xenial Xerus) Not vulnerable

Ubuntu 14.04 ESM (Trusty Tahr) Not vulnerable

Notes

AuthorNote
tyhicks
It isn't clear if this affects the upstream libarchive or not.
mdeslaur
marking as not-affected due to lack of details as of 2018-03-27

References