Multiple buffer overflows in the (1) heapaddentry and (2) relocatedir functions in archivereadsupportformat_iso9660.c in libarchive through 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ISO9660 image.