CVE-2015-8927: Medium severity oracle libarchive vulnerability
The tradencdecryptupdate function in archivereadsupportformatzip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted zip file, related to reading the password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8927?
CVE-2015-8927 has a severity rating that typically indicates a potential denial of service risk due to an out-of-bounds heap read.
How do I fix CVE-2015-8927?
To address CVE-2015-8927, users should upgrade to libarchive version 3.2.0 or later, which contains the necessary security patches.
What type of attack does CVE-2015-8927 allow?
CVE-2015-8927 allows remote attackers to perform denial of service attacks through crafted zip files.
Is CVE-2015-8927 exploitable by unauthenticated users?
Yes, CVE-2015-8927 can be exploited by unauthenticated remote attackers since it relies on processing crafted zip files.
What software is affected by CVE-2015-8927?
CVE-2015-8927 affects versions of libarchive prior to 3.2.0, particularly libarchive versions up to and including 3.1.901a.