CVE-2015-9261: Null Pointer Dereference
huftbuild in archival/libarchive/decompressgunzip.c in BusyBox before 1.27.2 misuses a pointer, causing segfaults and an application crash during an unzip operation on a specially crafted ZIP file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2015-9261.
What is the severity of CVE-2015-9261?
The severity of CVE-2015-9261 is medium with a severity value of 5.5.
Which software versions are affected by CVE-2015-9261?
CVE-2015-9261 affects BusyBox versions prior to 1.27.2.
How does CVE-2015-9261 impact the software?
CVE-2015-9261 can cause segfaults and application crashes during an unzip operation on a specially crafted ZIP file.
Are there any references available for CVE-2015-9261?
Yes, you can find more information about CVE-2015-9261 at the following references: [1](http://www.openwall.com/lists/oss-security/2015/10/25/3) [2](https://bugs.debian.org/803097) [3](https://git.busybox.net/busybox/commit/?id=1de25a6e87e0e627aa34298105a3d17c60a1f44e)