CVE-2016-1541: Libarchive
High severity, CVSS 8.8. EPSS: 10.3% chance of exploitation in the next 30 days.
Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to execute arbitrary code via crafted entry-size values in a ZIP archive.
Affected products
- Libarchive Libarchive: up to and including 3.1.901a
Published 2016-05-07. Last modified 2026-06-17.