CVE-2015-8926: Null Pointer Dereference
Published Sep 20, 2016
·Updated
The archivereadformatrarreaddata function in archivereadsupportformatrar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted rar archive.
Affected Software
8 affected components
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
Canonical Ubuntu Linux=16.04
SUSE Linux Enterprise Desktop=12-sp1
SUSE Linux Enterprise Server=12-sp1
SUSE Linux Enterprise Software Development Kit=12-sp1
Libarchive libarchive<=3.1.901a
Event History
Sep 20, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8926?
CVE-2015-8926 has a severity rating that indicates it can lead to a denial of service, specifically a crash.
2
How do I fix CVE-2015-8926?
To fix CVE-2015-8926, upgrade to libarchive version 3.2.0 or later.
3
Which software is affected by CVE-2015-8926?
CVE-2015-8926 affects multiple versions of Ubuntu Linux and SUSE Linux, specifically versions before libarchive 3.2.0.
4
Can CVE-2015-8926 be exploited remotely?
Yes, CVE-2015-8926 can be exploited by remote attackers through crafted rar archives.
5
What is the impact of exploiting CVE-2015-8926?
Exploiting CVE-2015-8926 can cause an application crash, resulting in denial of service.