CVE-2015-8920: Medium severity suse linux enterprise software development kit vulnerability
Published Sep 20, 2016
·Updated
The arreadheader function in archivereadsupportformatar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds stack read) via a crafted ar file.
Affected Software
8 affected components
Novell Suse Linux Enterprise Software Development Kit=12.0-sp1
Novell Suse Linux Enterprise Desktop=12.0-sp1
Novell Suse Linux Enterprise Server=12.0-sp1
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
Canonical Ubuntu Linux=16.04
Libarchive libarchive<=3.1.901a
Event History
Sep 20, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8920?
CVE-2015-8920 has a severity rating that indicates it can lead to a denial of service due to out-of-bounds stack read.
2
How do I fix CVE-2015-8920?
To fix CVE-2015-8920, upgrade libarchive to version 3.2.0 or later.
3
Which versions of software are affected by CVE-2015-8920?
CVE-2015-8920 affects libarchive versions before 3.2.0 and various distributions including SUSE and Ubuntu with specified versions.
4
What type of vulnerability is CVE-2015-8920?
CVE-2015-8920 is a vulnerability that allows for remote denial of service through crafted archive files.
5
Is CVE-2015-8920 exploitable remotely?
Yes, CVE-2015-8920 can be exploited remotely by providing a specially crafted ar file to the affected systems.