CVE-2015-8925

The readline function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read) via a crafted mtree file, related to newline parsing.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
NONE
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
Affected Products (NVD)
VendorProductVersion
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
15.10
canonicalubuntu_linux
16.04
libarchivelibarchive
𝑥
≤ 3.1.901a
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libarchive
bookworm
3.6.2-1+deb12u1
fixed
bookworm (security)
3.6.2-1+deb12u1
fixed
bullseye
3.4.3-2+deb11u1
fixed
sid
3.7.4-1.1
fixed
trixie
3.7.4-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libarchive
precise
Fixed 3.0.3-6ubuntu1.3
released
trusty
Fixed 3.1.2-7ubuntu2.3
released
wily
Fixed 3.1.2-11ubuntu0.15.10.2
released
xenial
Fixed 3.1.2-11ubuntu0.16.04.2
released
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
bsdcpio
RHEL 7
0:3.1.2-10.el7_2
fixed
bsdtar
RHEL 7
0:3.1.2-10.el7_2
fixed
libarchive
RHEL 7
0:3.1.2-10.el7_2
fixed
libarchive-devel
RHEL 7
0:3.1.2-10.el7_2
fixed