CVE-2017-15873: Integer Overflow
Published Oct 24, 2017
·Updated
Last updated 25 August 2025
Other sources
The getnextblock function in archival/libarchive/decompressbunzip2.c in BusyBox 1.27.2 has an Integer Overflow that may lead to a write access violation.
— Launchpad
Affected Software
8 affected componentsFixes available
Busybox Busybox=1.27.2
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
debian/busybox
1:1.30.1-61:1.30.1-6+deb11u11:1.35.0-4+deb12u11:1.37.0-61:1.37.0-10.1
Remediation
Event History
Oct 24, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:31 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·12:42 AM
RemedyDescriptionSeverityAffected Software
May 18, 2026
Data Sourced
via Debian·03:28 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2017-15873?
CVE-2017-15873 is a vulnerability in BusyBox 1.27.2 that allows for an Integer Overflow leading to a write access violation.
2
How severe is CVE-2017-15873?
CVE-2017-15873 has a severity rating of medium with a CVSS score of 5.5.
3
Which software versions are affected?
BusyBox 1.27.2 is affected by CVE-2017-15873.
4
How can I fix CVE-2017-15873?
To fix CVE-2017-15873, update your BusyBox installation to version 1.27.2-1ubuntu4 or later.
5
Where can I find more information about CVE-2017-15873?
You can find more information about CVE-2017-15873 on the BusyBox bug tracker, Git repository, and Debian mailing list.