← Vulnerability feed

Vulnerability record · CVE-2016-6250 · published 21 September 2016

CVE-2016-6250: Oracle linux integer overflow vulnerability

Oracle · Linux

Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors related to verifying filename lengths when writing an ISO9660 archive, which trigger a buffer overflow.

8.6 CVSS 3.0 High EPSS 6.3% · top 6.7% CWE-190 · Integer overflow
8.6CVSS 3.0 base score, v2 7.5
6.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
22References
17 Jun 2026Last modified by NVD

Description

Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors related to verifying filename lengths when writing an ISO9660 archive, which trigger a buffer overflow.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://rhn.redhat.com/errata/RHSA-2016-1844.html
http://www.openwall.com/lists/oss-security/2016/07/20/1 Release Notes
http://www.openwall.com/lists/oss-security/2016/07/21/3 Release Notes
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html Third Party Advisory
http://www.securityfocus.com/bid/92036 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1036431 Third Party AdvisoryVDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1347085 Issue TrackingThird Party Advisory
https://github.com/libarchive/libarchive/commit/3014e198 Issue TrackingPatch
https://github.com/libarchive/libarchive/files/295073/libarchiveOverflow.txt Issue Tracking
https://github.com/libarchive/libarchive/issues/711 Issue TrackingPatch
https://security.gentoo.org/glsa/201701-03
http://rhn.redhat.com/errata/RHSA-2016-1844.html
http://www.openwall.com/lists/oss-security/2016/07/20/1 Release Notes
http://www.openwall.com/lists/oss-security/2016/07/21/3 Release Notes
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html Third Party Advisory
http://www.securityfocus.com/bid/92036 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1036431 Third Party AdvisoryVDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1347085 Issue TrackingThird Party Advisory
https://github.com/libarchive/libarchive/commit/3014e198 Issue TrackingPatch
https://github.com/libarchive/libarchive/files/295073/libarchiveOverflow.txt Issue Tracking
https://github.com/libarchive/libarchive/issues/711 Issue TrackingPatch
https://security.gentoo.org/glsa/201701-03

Track CVE-2016-6250 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed7.8CVE-2015-5287ABRT abrt-hook-ccpp symlink privilege escalationThe abrt-hook-ccpp helper in Red Hat's Automatic Bug Reporting Tool (ABRT) before 2.7.1 follows symlinks on files with predictable names, letting a l…KEVEPSS 5.0%analysed7.8CVE-2014-3153Linux Kernel futex_requeue Local Privilege EscalationThe futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 fails to verify that a FUTEX_REQUEUE call supplies two different fute…KEVEPSS 37%analysed5.5CVE-2016-3718ImageMagick HTTP/FTP coders allow server-side request forgery via crafted imageImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 mishandles the HTTP and FTP coders, letting a crafted image trigger server-side request forgery. A…KEVEPSS 77%analysed5.5CVE-2016-3715ImageMagick EPHEMERAL coder allows arbitrary file deletionThe EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 lets a crafted image cause deletion of arbitrary files. This is part of the…KEVEPSS 75%analysed5.5CVE-2014-0196Linux kernel n_tty_write race condition allows local privilege escalationThe n_tty_write function in the Linux kernel through 3.14.3 mishandles tty driver access in the LECHO & !OPOST case, creating a race condition betwee…KEVEPSS 22%analysed

Source: NIST National Vulnerability Database (record CVE-2016-6250), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.