CVE-2013-0211
EPSS 1.2%
Description
Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of service (crash) via unspecified vectors, which triggers an improper conversion between unsigned and signed types, leading to a buffer overflow.
How to fix CVE-2013-0211
To remediate CVE-2013-0211, upgrade the affected package to a fixed version below.
- Debian/libarchive—upgrade to 3.0.4-3 or later
Is CVE-2013-0211 being exploited?
Low — EPSS is 1.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 3.0.4-3