The archive_wstring_append_from_mbs function in archive_string.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive file. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-10209