Your submission was sent successfully! Close

CVE-2017-13816

Published: 13 November 2017

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "libarchive" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted archive file.

Notes

AuthorNote
tyhicks
It isn't clear if this affects the upstream libarchive or not.
mdeslaur
marking as not-affected due to lack of details as of 2018-03-27
Priority

Medium

CVSS 3 base score: 7.8

Status

Package Release Status
libarchive
Launchpad, Ubuntu, Debian
artful Not vulnerable

precise Does not exist

trusty Not vulnerable

upstream Needs triage

xenial Not vulnerable

zesty Ignored
(reached end-of-life)