Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2015-8934
The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted rar file.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.024
EPSS Ranking
84.2%
CVSS Severity
CVSS v3 Score
5.5
CVSS v2 Score
4.3
References
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00025.html
http://rhn.redhat.com/errata/RHSA-2016-1844.html
http://www.debian.org/security/2016/dsa-3657
http://www.openwall.com/lists/oss-security/2016/06/17/2
http://www.openwall.com/lists/oss-security/2016/06/17/5
http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
http://www.securityfocus.com/bid/91409
http://www.ubuntu.com/usn/USN-3033-1
https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
https://github.com/libarchive/libarchive/issues/521
https://security.gentoo.org/glsa/201701-03
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00025.html
http://rhn.redhat.com/errata/RHSA-2016-1844.html
http://www.debian.org/security/2016/dsa-3657
http://www.openwall.com/lists/oss-security/2016/06/17/2
http://www.openwall.com/lists/oss-security/2016/06/17/5
http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
http://www.securityfocus.com/bid/91409
http://www.ubuntu.com/usn/USN-3033-1
https://blog.fuzzing-project.org/47-Many-invalid-memory-access-issues-in-libarchive.html
https://github.com/libarchive/libarchive/issues/521
https://security.gentoo.org/glsa/201701-03
Products affected by CVE-2015-8934
Libarchive
»
Libarchive
»
Version:
N/A
cpe:2.3:a:libarchive:libarchive:-
Libarchive
»
Libarchive
»
Version:
2.6.0
cpe:2.3:a:libarchive:libarchive:2.6.0
Libarchive
»
Libarchive
»
Version:
2.6.1
cpe:2.3:a:libarchive:libarchive:2.6.1
Libarchive
»
Libarchive
»
Version:
2.6.2
cpe:2.3:a:libarchive:libarchive:2.6.2
Libarchive
»
Libarchive
»
Version:
2.7.0
cpe:2.3:a:libarchive:libarchive:2.7.0
Libarchive
»
Libarchive
»
Version:
2.7.1
cpe:2.3:a:libarchive:libarchive:2.7.1
Libarchive
»
Libarchive
»
Version:
2.8.0
cpe:2.3:a:libarchive:libarchive:2.8.0
Libarchive
»
Libarchive
»
Version:
2.8.1
cpe:2.3:a:libarchive:libarchive:2.8.1
Libarchive
»
Libarchive
»
Version:
2.8.2
cpe:2.3:a:libarchive:libarchive:2.8.2
Libarchive
»
Libarchive
»
Version:
2.8.3
cpe:2.3:a:libarchive:libarchive:2.8.3
Libarchive
»
Libarchive
»
Version:
2.8.4
cpe:2.3:a:libarchive:libarchive:2.8.4
Libarchive
»
Libarchive
»
Version:
2.8.5
cpe:2.3:a:libarchive:libarchive:2.8.5
Libarchive
»
Libarchive
»
Version:
3.0.0a
cpe:2.3:a:libarchive:libarchive:3.0.0a
Libarchive
»
Libarchive
»
Version:
3.0.1b
cpe:2.3:a:libarchive:libarchive:3.0.1b
Libarchive
»
Libarchive
»
Version:
3.0.2
cpe:2.3:a:libarchive:libarchive:3.0.2
Libarchive
»
Libarchive
»
Version:
3.0.3
cpe:2.3:a:libarchive:libarchive:3.0.3
Libarchive
»
Libarchive
»
Version:
3.0.4
cpe:2.3:a:libarchive:libarchive:3.0.4
Libarchive
»
Libarchive
»
Version:
3.1.0
cpe:2.3:a:libarchive:libarchive:3.1.0
Libarchive
»
Libarchive
»
Version:
3.1.1
cpe:2.3:a:libarchive:libarchive:3.1.1
Libarchive
»
Libarchive
»
Version:
3.1.2
cpe:2.3:a:libarchive:libarchive:3.1.2
Libarchive
»
Libarchive
»
Version:
3.1.900a
cpe:2.3:a:libarchive:libarchive:3.1.900a
Libarchive
»
Libarchive
»
Version:
3.1.901a
cpe:2.3:a:libarchive:libarchive:3.1.901a
Canonical
»
Ubuntu Linux
»
Version:
12.04
cpe:2.3:o:canonical:ubuntu_linux:12.04
Canonical
»
Ubuntu Linux
»
Version:
14.04
cpe:2.3:o:canonical:ubuntu_linux:14.04
Canonical
»
Ubuntu Linux
»
Version:
15.10
cpe:2.3:o:canonical:ubuntu_linux:15.10
Canonical
»
Ubuntu Linux
»
Version:
16.04
cpe:2.3:o:canonical:ubuntu_linux:16.04
Suse
»
Linux Enterprise Desktop
»
Version:
12
cpe:2.3:o:suse:linux_enterprise_desktop:12
Suse
»
Linux Enterprise Server
»
Version:
12
cpe:2.3:o:suse:linux_enterprise_server:12
Suse
»
Linux Enterprise Software Development Kit
»
Version:
12
cpe:2.3:o:suse:linux_enterprise_software_development_kit:12
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved