CVE-2011-1777

NameCVE-2011-1777
DescriptionMultiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functions in archive_read_support_format_iso9660.c in libarchive through 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ISO9660 image.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-2413-1
NVD severitymedium (attack range: remote)
Debian Bugs651844

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libarchive (PTS)jessie, jessie (security)3.1.2-11+deb8u3fixed
stretch3.2.2-2fixed
buster, sid3.2.2-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libarchivesource(unstable)2.8.5-5medium651844
libarchivesourcesqueeze2.8.4-1+squeeze1mediumDSA-2413-1

Search for package or bug name: Reporting problems