CVE-2015-8918: Buffer Overflow
Published Sep 20, 2016
·Updated
The archivestringappend function in archivestring.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted cab files, related to "overlapping memcpy."
Affected Software
4 affected components
Novell Suse Linux Enterprise Software Development Kit=12.0-sp1
Novell Suse Linux Enterprise Desktop=12.0-sp1
Novell Suse Linux Enterprise Server=12.0-sp1
Libarchive libarchive<=3.1.901a
Remediation
Patch Available
Event History
Sep 20, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8918?
CVE-2015-8918 has a high severity level due to its potential to cause denial of service attacks.
2
How do I fix CVE-2015-8918?
To fix CVE-2015-8918, update libarchive to version 3.2.0 or later, or apply patches provided by your system vendor.
3
Which software is affected by CVE-2015-8918?
CVE-2015-8918 affects libarchive versions up to 3.1.901a and SUSE Linux Enterprise versions 12.0 with SP1.
4
What types of attacks exploit CVE-2015-8918?
CVE-2015-8918 can be exploited by attackers using crafted cab files to crash the affected software.
5
Is CVE-2015-8918 specific to certain operating systems?
Yes, CVE-2015-8918 specifically impacts SUSE Linux Enterprise and libarchive applications on affected systems.