The vendor has not yet reached a final affected or unaffected determination for these products.
- bsdtar as a component of Red Hat Enterprise Linux 10
- libarchive as a component of Red Hat Enterprise Linux 10
- libarchive-devel as a component of Red Hat Enterprise Linux 10
- libarchive.src as a component of Red Hat Enterprise Linux 10
- libarchive as a component of Red Hat Enterprise Linux 6
- libarchive-devel as a component of Red Hat Enterprise Linux 6
- libarchive.src as a component of Red Hat Enterprise Linux 6
- openshift/ose-rhel-coreos-9 as a component of Red Hat OpenShift Container Platform 4
- Summary
- A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
