CVE-2015-8923: Input Validation
Published Sep 20, 2016
·Updated
The processextra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file.
Affected Software
8 affected components
Libarchive libarchive<=3.1.901a
Novell Suse Linux Enterprise Software Development Kit=12.0-sp1
Novell Suse Linux Enterprise Desktop=12.0-sp1
Novell Suse Linux Enterprise Server=12.0-sp1
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
Canonical Ubuntu Linux=16.04
Event History
Sep 20, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8923?
CVE-2015-8923 is classified as a denial of service vulnerability that can lead to application crashes.
2
How do I fix CVE-2015-8923?
To fix CVE-2015-8923, you should upgrade libarchive to version 3.2.0 or later.
3
What kind of attack is facilitated by CVE-2015-8923?
CVE-2015-8923 allows remote attackers to cause a denial of service by using a crafted zip file.
4
Which versions of libarchive are affected by CVE-2015-8923?
Versions of libarchive prior to 3.2.0, including all versions up to and including 3.1.901a, are affected by CVE-2015-8923.
5
What systems are impacted by CVE-2015-8923?
CVE-2015-8923 affects various systems, including certain versions of SUSE Linux and Ubuntu.