CVE-2015-8922: Null Pointer Dereference
Published Sep 20, 2016
·Updated
The readCodersInfo function in archivereadsupportformat7zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted 7z file, related to the 7zfolder struct.
Affected Software
9 affected components
Libarchive libarchive<=3.1.901a
Novell Suse Linux Enterprise Software Development Kit=12.0-sp1
Novell Suse Linux Enterprise Desktop=12.0-sp1
Novell Suse Linux Enterprise Server=12.0-sp1
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
Canonical Ubuntu Linux=16.04
Oracle Linux=7
Event History
Sep 20, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8922?
CVE-2015-8922 has a severity rating that can lead to denial of service due to a NULL pointer dereference.
2
How do I fix CVE-2015-8922?
To fix CVE-2015-8922, update libarchive to version 3.2.0 or later.
3
What impact does CVE-2015-8922 have on affected systems?
CVE-2015-8922 can cause a crash of the application processing a crafted 7z file.
4
Which software versions are vulnerable to CVE-2015-8922?
Vulnerable versions of libarchive are those prior to 3.2.0, including versions up to 3.1.901a.
5
Is CVE-2015-8922 targeted by attackers?
Yes, CVE-2015-8922 can be exploited by attackers using specially crafted 7z files to cause service disruption.