4.3
CVSSv2

CVE-2015-8915

Published: 20/09/2016 Updated: 30/11/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

bsdcpio in libarchive prior to 3.2.0 allows remote malicious users to cause a denial of service (invalid read and crash) via crafted cpio file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libarchive libarchive

Vendor Advisories

Debian Bug report logs - #784213 libarchive: crash or infinite loop via malformed cpio archive Package: src:libarchive; Maintainer for src:libarchive is Peter Pentchev <roam@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 4 May 2015 05:30:06 UTC Severity: important Tags: fixed-upstream, ...
bsdcpio in libarchive before 320 allows remote attackers to cause a denial of service (invalid read and crash) via crafted cpio file ...