CVE-2015-8929: Buffer Overflow
Published Sep 20, 2016
·Updated
Memory leak in the archivereadgetextract function in archivereadextract2.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service via a tar file.
Affected Software
4 affected components
SUSE Linux Enterprise Desktop=12-sp1
SUSE Linux Enterprise Server=12-sp1
SUSE Linux Enterprise Software Development Kit=12-sp1
Libarchive libarchive<=3.1.901a
Event History
Sep 20, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8929?
CVE-2015-8929 is classified as a denial of service vulnerability.
2
How do I fix CVE-2015-8929?
To fix CVE-2015-8929, upgrade libarchive to version 3.2.0 or later.
3
What causes CVE-2015-8929?
CVE-2015-8929 is caused by a memory leak in the __archive_read_get_extract function.
4
Which versions of software are affected by CVE-2015-8929?
CVE-2015-8929 affects libarchive versions prior to 3.2.0 and SUSE Linux Enterprise Desktop and Server versions 12-sp1.
5
How can CVE-2015-8929 be exploited?
CVE-2015-8929 can be exploited by remote attackers utilizing a specially crafted tar file.