CVE-2015-8927

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
20/09/2016
Last modified:
12/04/2025

Description

The trad_enc_decrypt_update function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted zip file, related to reading the password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:* 3.1.901a (including)