CVE-2013-0211: Canonical Ubuntu Linux

Medium severity, CVSS 5.0. EPSS: 3.9% chance of exploitation in the next 30 days.

Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of service (crash) via unspecified vectors, which triggers an improper conversion between unsigned and signed types, leading to a buffer overflow.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 14.10 only
  • Fedoraproject Fedora: version 17 only; version 18 only
  • Freebsd Freebsd: version 9.3 only
  • Libarchive Libarchive: up to and including 3.1.2
  • Opensuse Opensuse: version 13.1 only; version 13.2 only

Published 2013-09-30. Last modified 2026-06-16.