CVE-2015-8928: Medium severity ubuntu vulnerability
Published Sep 20, 2016
·Updated
The processaddentry function in archivereadsupportformatmtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file.
Affected Software
8 affected components
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
Canonical Ubuntu Linux=16.04
Libarchive libarchive<=3.1.901a
SUSE Linux Enterprise Desktop=12-sp1
SUSE Linux Enterprise Server=12-sp1
SUSE Linux Enterprise Software Development Kit=12-sp1
Event History
Sep 20, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8928?
CVE-2015-8928 has a moderate severity level, primarily allowing denial of service through an out-of-bounds read.
2
How do I fix CVE-2015-8928?
To fix CVE-2015-8928, ensure you update libarchive to version 3.2.0 or later.
3
Which software is affected by CVE-2015-8928?
CVE-2015-8928 affects libarchive versions prior to 3.2.0 and certain Ubuntu and SUSE Linux distributions.
4
Can CVE-2015-8928 be exploited remotely?
Yes, CVE-2015-8928 can be exploited remotely through a crafted mtree file.
5
What type of vulnerability is CVE-2015-8928?
CVE-2015-8928 is an out-of-bounds read vulnerability leading to potential denial of service.