Loading
Generated remediation guidance and an executive summary. No account required.
libarchive 3.3.2 allows remote attackers to cause a denial of service (xml_data heap-based buffer over-read and application crash) via a crafted xar archive, related to the mishandling of empty strings in the atol8 function in archive_read_support_format_xar.c.
Use CWE-125, Libarchive vendor hub and Libarchive product page to widen CVE-2017-14166 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-5914, CVE-2024-48958 and CVE-2024-48957 for nearby disclosures in the same product family.