CVE-2015-8929

Severity
5.5MEDIUM
EPSS
0.3%
top 51.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 20
Latest updateMay 17

Description

Memory leak in the __archive_read_get_extract function in archive_read_extract2.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service via a tar file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

🔴Vulnerability Details

3
GHSA
GHSA-24gg-vmf8-whvm: Memory leak in the __archive_read_get_extract function in archive_read_extract22022-05-17
CVEList
CVE-2015-8929: Memory leak in the __archive_read_get_extract function in archive_read_extract22016-09-20
OSV
CVE-2015-8929: Memory leak in the __archive_read_get_extract function in archive_read_extract22016-09-20

📋Vendor Advisories

2
Red Hat
libarchive: Memory leak in TAR parser2016-06-17
Debian
CVE-2015-8929: libarchive - Memory leak in the __archive_read_get_extract function in archive_read_extract2....2015

💬Community

1
Bugzilla
CVE-2015-8929 libarchive: Memory leak in TAR parser2016-06-22
CVE-2015-8929 (MEDIUM CVSS 5.5) | Memory leak in the __archive_read_g | cvebase.io