Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-8927

Опубликовано: 20 сент. 2016
Источник: debian

Описание

The trad_enc_decrypt_update function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted zip file, related to reading the password.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libarchivefixed3.2.0-2package
libarchivenot-affectedjessiepackage
libarchivenot-affectedwheezypackage

Примечания

  • https://github.com/libarchive/libarchive/issues/523

  • Fixed by https://github.com/libarchive/libarchive/commit/eff35d4

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 9 лет назад

The trad_enc_decrypt_update function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted zip file, related to reading the password.

CVSS3: 3
redhat
больше 9 лет назад

The trad_enc_decrypt_update function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted zip file, related to reading the password.

CVSS3: 5.5
nvd
больше 9 лет назад

The trad_enc_decrypt_update function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted zip file, related to reading the password.

CVSS3: 5.5
github
больше 3 лет назад

The trad_enc_decrypt_update function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted zip file, related to reading the password.