Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to execute arbitrary code via crafted entry-size values in a ZIP archive. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-1541