CVE-2015-8919: Buffer Overflow
Published Sep 20, 2016
·Updated
The lhareadfileextendedheader function in archivereadsupportformatlha.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap) via a crafted (1) lzh or (2) lha file.
Affected Software
8 affected components
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
Canonical Ubuntu Linux=16.04
Libarchive libarchive<=3.1.901a
Novell Suse Linux Enterprise Software Development Kit=12.0-sp1
Novell Suse Linux Enterprise Desktop=12.0-sp1
Novell Suse Linux Enterprise Server=12.0-sp1
Remediation
Patch Available
Event History
Sep 20, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8919?
CVE-2015-8919 is classified as a denial of service vulnerability due to potential out-of-bounds heap access.
2
How can I mitigate CVE-2015-8919?
Mitigation for CVE-2015-8919 involves upgrading to libarchive version 3.2.0 or higher.
3
Which software is affected by CVE-2015-8919?
CVE-2015-8919 affects multiple versions of Ubuntu and SUSE Linux that use libarchive versions prior to 3.2.0.
4
What causes CVE-2015-8919?
CVE-2015-8919 is caused by the lha_read_file_extended_header function mishandling crafted lzh or lha files.
5
Can CVE-2015-8919 be exploited remotely?
Yes, CVE-2015-8919 allows remote attackers to exploit the vulnerability by sending a specially crafted lha or lzh file.