Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8932

Опубликовано: 17 июн. 2016
Источник: redhat
CVSS3: 3.5
CVSS2: 3.5

Описание

The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left shift.

Undefined behavior (invalid left shift) was discovered in libarchive, in how Compress streams are identified. This could cause certain files to be mistakenly identified as Compress archives and fail to read.

Дополнительная информация

Статус:

Low
Дефект:
CWE-682
https://bugzilla.redhat.com/show_bug.cgi?id=1348780libarchive: Undefined behavior / invalid shiftleft in TAR parser

3.5 Low

CVSS3

3.5 Low

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 9 лет назад

The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left shift.

CVSS3: 5.5
nvd
почти 9 лет назад

The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left shift.

CVSS3: 5.5
debian
почти 9 лет назад

The compress_bidder_init function in archive_read_support_filter_compr ...

CVSS3: 5.5
github
около 3 лет назад

The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left shift.

oracle-oval
почти 9 лет назад

ELSA-2016-1850: libarchive security update (IMPORTANT)

3.5 Low

CVSS3

3.5 Low

CVSS2