5.5
CVSSv3

CVE-2015-8927

Published: 20/09/2016 Updated: 01/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The trad_enc_decrypt_update function in archive_read_support_format_zip.c in libarchive prior to 3.2.0 allows remote malicious users to cause a denial of service (out-of-bounds heap read and crash) via a crafted zip file, related to reading the password.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libarchive libarchive

Vendor Advisories

The trad_enc_decrypt_update function in archive_read_support_format_zipc in libarchive before 320 allows remote attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted zip file, related to reading the password ...