CVE-2015-8915: Medium severity oracle libarchive vulnerability
Published Sep 20, 2016
·Updated
bsdcpio in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read and crash) via crafted cpio file.
Affected Software
1 affected component
Libarchive libarchive<=3.1.901a
Event History
Sep 20, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8915?
CVE-2015-8915 is classified as a denial of service vulnerability that can lead to application crashes.
2
How do I fix CVE-2015-8915?
To fix CVE-2015-8915, upgrade libarchive to version 3.2.0 or later.
3
What types of attacks can exploit CVE-2015-8915?
CVE-2015-8915 can be exploited by remote attackers using specially crafted cpio files.
4
In which versions of libarchive is CVE-2015-8915 present?
CVE-2015-8915 affects libarchive versions prior to 3.2.0.
5
What component of libarchive is vulnerable in CVE-2015-8915?
The vulnerability in CVE-2015-8915 resides in the bsdcpio component of libarchive.