CVE-2015-8934: Medium severity suse linux enterprise desktop vulnerability
The copyfromlzsswindow function in archivereadsupportformatrar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted rar file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8934?
CVE-2015-8934 is classified as a moderate severity vulnerability due to its potential to cause denial of service through out-of-bounds heap reads.
How do I fix CVE-2015-8934?
To fix CVE-2015-8934, upgrade to libarchive version 3.2.1 or later, which contains the necessary patches.
Which software is affected by CVE-2015-8934?
CVE-2015-8934 affects multiple versions of SUSE Linux Enterprise Desktop, SUSE Linux Enterprise Server, and various Ubuntu Linux versions.
What kind of attack does CVE-2015-8934 facilitate?
CVE-2015-8934 allows remote attackers to exploit crafted RAR files, leading to a denial of service.
Is CVE-2015-8934 exploitable in all environments?
CVE-2015-8934 is exploitable primarily in systems running the affected versions of libarchive, especially when processing untrusted RAR files.