CVE-2015-2063: Buffer Overflow
Published Jan 9, 2015
·Updated
Integer overflow in unace 1.2b allows remote attackers to cause a denial of service (crash) via a small file header in an ace archive, which triggers a buffer overflow.
Affected Software
3 affected componentsFixes available
debian/unace<=1.2b-7, <=1.2b-10, <=1.2b-11
1.2b-121.2b-7+deb6u11.2b-10+deb7u1
debian/unace
1.2b-191.2b-231.2b-24
WinAce Unace=1.2b
Event History
Mar 9, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Aug 6, 2024
Data Sourced
via Debian·05:11 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2015-2063?
CVE-2015-2063 has a medium severity level due to its potential to cause a denial of service.
2
How do I fix CVE-2015-2063?
To fix CVE-2015-2063, upgrade unace to a version that is not vulnerable, such as 1.2b-19 or later.
3
Which versions of unace are affected by CVE-2015-2063?
CVE-2015-2063 affects unace versions up to and including 1.2b-12.
4
What type of vulnerability is CVE-2015-2063?
CVE-2015-2063 is classified as an integer overflow vulnerability that can lead to buffer overflow.
5
Can CVE-2015-2063 be exploited remotely?
Yes, CVE-2015-2063 can be exploited remotely through specially crafted ace archive files.