CVE-2015-8932: Input Validation
Published Sep 20, 2016
·Updated
The compressbidderinit function in archivereadsupportfiltercompress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left shift.
Affected Software
11 affected componentsFixes available
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
Canonical Ubuntu Linux=16.04
Debian Debian Linux=7.0
Debian Debian Linux=8.0
SUSE Linux Enterprise Desktop=12-sp1
SUSE Linux Enterprise Server=12-sp1
SUSE Linux Enterprise Software Development Kit=12-sp1
Libarchive libarchive<=3.1.901a
debian/libarchive
3.4.3-2+deb11u13.4.3-2+deb11u33.6.2-1+deb12u33.6.2-1+deb12u23.7.4-43.8.5-1
Remediation
Patch Available
Event History
Sep 20, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Feb 19, 2026
Data Sourced
via Debian·12:14 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2015-8932?
CVE-2015-8932 has a severity rating that allows remote attackers to cause a denial of service (crash) through a crafted tar file.
2
How do I fix CVE-2015-8932?
To fix CVE-2015-8932, upgrade to libarchive version 3.2.0 or later.
3
What does CVE-2015-8932 affect?
CVE-2015-8932 affects libarchive versions before 3.2.0.
4
Can CVE-2015-8932 impact any operating systems?
Yes, CVE-2015-8932 can impact various operating systems including Debian and Ubuntu versions prior to the patched libarchive version.
5
What type of vulnerability is CVE-2015-8932?
CVE-2015-8932 is a denial of service vulnerability related to improper handling of crafted tar files.