CVE-2015-8930: Input Validation
bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (infinite loop) via an ISO with a directory that is a member of itself.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8930?
CVE-2015-8930 has been classified with a medium severity level due to its potential to cause denial of service through an infinite loop.
How do I fix CVE-2015-8930?
To fix CVE-2015-8930, update libarchive to version 3.2.0 or later, or apply the appropriate patches for your affected operating system.
Which software is affected by CVE-2015-8930?
CVE-2015-8930 affects multiple versions of libarchive prior to 3.2.0 and specific versions of SUSE Linux and Ubuntu Linux.
What type of vulnerability is CVE-2015-8930?
CVE-2015-8930 is a denial of service vulnerability that occurs due to an infinite loop in bsdtar when processing certain ISO files.
Can CVE-2015-8930 lead to data loss?
CVE-2015-8930 primarily causes a denial of service and does not directly lead to data loss, but it may disrupt system operations.