Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-8932

Опубликовано: 20 сент. 2016
Источник: debian
EPSS Низкий

Описание

The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left shift.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libarchivefixed3.2.0-2package

Примечания

  • https://github.com/libarchive/libarchive/issues/547

  • Fixed by: https://github.com/libarchive/libarchive/commit/f0b1dbbc325a2d922015eee402b72edd422cb9ea (v3.1.900a)

  • and part of https://github.com/libarchive/libarchive/commit/55ce98e829eda3a4356c2be64a778d8740c2cf6c (v3.1.900a)

  • and https://github.com/libarchive/libarchive/commit/618618c8a6be453f79e0bdbdeab6e1dd8bf429b3 (v3.1.900a)

  • Part of the problematic code was introduced with commit bf4f6ec64ef3edefbc41172692868fb8df514805

  • to fix https://github.com/libarchive/libarchive/issues/356

EPSS

Процентиль: 69%
0.00626
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 9 лет назад

The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left shift.

CVSS3: 3.5
redhat
около 9 лет назад

The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left shift.

CVSS3: 5.5
nvd
почти 9 лет назад

The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left shift.

CVSS3: 5.5
github
около 3 лет назад

The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left shift.

oracle-oval
почти 9 лет назад

ELSA-2016-1850: libarchive security update (IMPORTANT)

EPSS

Процентиль: 69%
0.00626
Низкий