First published: Tue Oct 24 2017(Updated: )
archival/libarchive/decompress_unlzma.c in BusyBox 1.27.2 has an Integer Underflow that leads to a read access violation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BusyBox | =1.27.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15874 has a medium severity rating due to an integer underflow which can lead to a read access violation.
To fix CVE-2017-15874, update BusyBox to version 1.28.0 or later to ensure the vulnerability is patched.
CVE-2017-15874 affects BusyBox version 1.27.2 specifically.
CVE-2017-15874 is classified as an integer underflow vulnerability.
CVE-2017-15874 impacts the decompress_unlzma.c component within BusyBox.