Bugzilla – Bug 998115
VUL-1: CVE-2016-7166: libarchive: Denial of service using a crafted gzip file
Last modified: 2019-12-11 16:37:26 UTC
rh#1347086 A specially crafted gzip file can cause libarchive to allocate memory without limit, eventually leading to a crash. External references: https://github.com/libarchive/libarchive/issues/660 Upstream fix: https://github.com/libarchive/libarchive/commit/6e06b1c89 References: https://bugzilla.redhat.com/show_bug.cgi?id=1347086 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-7166 http://seclists.org/oss-sec/2016/q3/454 http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-7166.html
bugbot adjusting priority
already done
all done