CVE-2015-8924: Medium severity oracle libarchive vulnerability
Published Sep 20, 2016
·Updated
The archivereadformattarreadheader function in archivereadsupportformattar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tar file.
Affected Software
8 affected components
Libarchive libarchive<=3.1.901a
Novell Suse Linux Enterprise Software Development Kit=12.0-sp1
Novell Suse Linux Enterprise Desktop=12.0-sp1
Novell Suse Linux Enterprise Server=12.0-sp1
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
Canonical Ubuntu Linux=16.04
Event History
Sep 20, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8924?
CVE-2015-8924 has been classified as a denial of service vulnerability causing out-of-bounds read issues.
2
How do I fix CVE-2015-8924?
To fix CVE-2015-8924, upgrade libarchive to version 3.2.0 or later.
3
What type of attack does CVE-2015-8924 enable?
CVE-2015-8924 allows remote attackers to perform denial of service attacks through crafted tar files.
4
Which versions of libarchive are affected by CVE-2015-8924?
Libarchive versions before 3.2.0 are affected by CVE-2015-8924.
5
What systems are known to be affected by CVE-2015-8924?
CVE-2015-8924 affects various SUSE Linux and Ubuntu versions, primarily before their respective patches were applied.