CVE-2017-15874: Integer Underflow
Published Oct 24, 2017
·Updated
archival/libarchive/decompressunlzma.c in BusyBox 1.27.2 has an Integer Underflow that leads to a read access violation.
Affected Software
1 affected component
Busybox Busybox=1.27.2
Remediation
Patch Available
Event History
Oct 24, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-15874?
CVE-2017-15874 has a medium severity rating due to an integer underflow which can lead to a read access violation.
2
How do I fix CVE-2017-15874?
To fix CVE-2017-15874, update BusyBox to version 1.28.0 or later to ensure the vulnerability is patched.
3
Which versions of BusyBox are affected by CVE-2017-15874?
CVE-2017-15874 affects BusyBox version 1.27.2 specifically.
4
What type of vulnerability is CVE-2017-15874?
CVE-2017-15874 is classified as an integer underflow vulnerability.
5
What components in BusyBox does CVE-2017-15874 impact?
CVE-2017-15874 impacts the decompress_unlzma.c component within BusyBox.