CVE-2015-8921: High severity suse linux enterprise software development kit vulnerability
Published Sep 20, 2016
·Updated
The aestrtofflags function in archiveentry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file.
Affected Software
8 affected components
Novell Suse Linux Enterprise Software Development Kit=12.0-sp1
Novell Suse Linux Enterprise Desktop=12.0-sp1
Novell Suse Linux Enterprise Server=12.0-sp1
Libarchive libarchive<=3.1.901a
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
Canonical Ubuntu Linux=16.04
Event History
Sep 20, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8921?
CVE-2015-8921 has a medium severity level as it can lead to denial of service due to an out-of-bounds read.
2
How do I fix CVE-2015-8921?
To fix CVE-2015-8921, upgrade to libarchive version 3.2.0 or later.
3
Which software is affected by CVE-2015-8921?
CVE-2015-8921 affects libarchive versions up to 3.1.901a and specific versions of SUSE Linux and Ubuntu Linux.
4
Can CVE-2015-8921 be exploited remotely?
Yes, CVE-2015-8921 can be exploited by remote attackers through crafted mtree files.
5
What types of attacks does CVE-2015-8921 allow?
CVE-2015-8921 allows for denial of service attacks via an out-of-bounds read.