Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8934

Опубликовано: 17 июн. 2016
Источник: redhat
CVSS3: 3.7
CVSS2: 3.5
EPSS Низкий

Описание

The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted rar file.

A vulnerability was found in libarchive. A specially crafted RAR file could cause the application to read memory beyond the end of the decompression buffer.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libarchiveNot affected
Red Hat Enterprise Linux 7libarchiveFixedRHSA-2016:184412.09.2016

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-228->CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1349229libarchive: out of bounds heap read in RAR parser

EPSS

Процентиль: 84%
0.0241
Низкий

3.7 Low

CVSS3

3.5 Low

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 9 лет назад

The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted rar file.

CVSS3: 5.5
nvd
почти 9 лет назад

The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted rar file.

CVSS3: 5.5
debian
почти 9 лет назад

The copy_from_lzss_window function in archive_read_support_format_rar. ...

CVSS3: 5.5
github
около 3 лет назад

The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted rar file.

suse-cvrf
около 9 лет назад

Security update for libarchive

EPSS

Процентиль: 84%
0.0241
Низкий

3.7 Low

CVSS3

3.5 Low

CVSS2