5
CVSSv2

CVE-2015-8921

Published: 20/09/2016 Updated: 12/09/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The ae_strtofflags function in archive_entry.c in libarchive prior to 3.2.0 allows remote malicious users to cause a denial of service (out-of-bounds read) via a crafted mtree file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

novell suse linux enterprise server 12.0

novell suse linux enterprise desktop 12.0

novell suse linux enterprise software development kit 12.0

libarchive libarchive

canonical ubuntu linux 12.04

canonical ubuntu linux 16.04

canonical ubuntu linux 15.10

canonical ubuntu linux 14.04

Vendor Advisories

libarchive could be made to crash or run programs if it opened a specially crafted file ...
A flaw was found in the way libarchive handled hardlink archive entries of non-zero size Combined with flaws in libarchive's file system sandboxing, this issue could cause an application using libarchive to overwrite arbitrary files with arbitrary data from the archive (CVE-2016-5418) Multiple out-of-bounds write flaws were found in libarchive S ...
A vulnerability was found in libarchive A specially crafted mtree file could cause libarchive to read beyond a statically declared structure, potentially disclosing application memory ...