CVE-2016-4300 is an integer overflow vulnerability in the libarchive library, specifically within the read_SubStreamsInfo function, affecting versions prior to 3.2.1. This flaw allows remote attackers to execute arbitrary code by crafting a malicious 7zip file with an excessive number of substreams, leading to a heap-based buffer overflow. Rated with a CVSS score of 7.8 (HIGH), it requires user interaction (e.g., opening a malicious file) but can result in high confidentiality, integrity, and availability impacts. While no public exploit code (Metasploit, Nuclei, ExploitDB) or KEV entries exist, the vulnerability has garnered some community discussion and media coverage, indicating awareness despite its inactive status on hot lists.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.2.0CPE matchmatch criteria | cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:* | ||
7.2CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_hpc_node_eus:7.2:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.