Stack-based buffer overflow in the safe_fprintf function in tar/util.c in libarchive 3.2.1 allows remote attackers to cause a denial of service via a crafted non-printable multibyte character in a filename.
{
"unresolved_ranges": [
{
"vendor_product": "opensuse:leap",
"source": "CPE_STRING",
"extracted_events": [
{
"introduced": "42.2"
},
{
"last_affected": "42.2"
}
],
"cpes": [
"cpe:2.3:o:opensuse:leap:42.2:*:*:*:*:*:*:*"
]
}
]
}{
"cpe": "cpe:2.3:a:libarchive:libarchive:3.2.1:*:*:*:*:*:*:*",
"source": [
"CPE_STRING",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "3.2.1"
},
{
"last_affected": "3.2.1"
}
]
}
[
{
"id": "CVE-2016-8687-2b8436e1",
"target": {
"file": "tar/util.c"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"274947236785517941576769110957933520277",
"162673665667336708429251698339556414402",
"30924440026046384237080647977686539477",
"6762232481255207823455611895071712144"
]
},
"signature_version": "v1",
"source": "https://github.com/libarchive/libarchive/commit/e37b620fe8f14535d737e89a4dcabaed4517bf1a",
"signature_type": "Line"
},
{
"id": "CVE-2016-8687-f2b8937e",
"target": {
"function": "safe_fprintf",
"file": "tar/util.c"
},
"deprecated": false,
"digest": {
"function_hash": "306124670893253162293110805501400168732",
"length": 1454.0
},
"signature_version": "v1",
"source": "https://github.com/libarchive/libarchive/commit/e37b620fe8f14535d737e89a4dcabaed4517bf1a",
"signature_type": "Function"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-8687.json"
"2026-08-07T14:48:28Z"