Lucene search

K
f5F5F5:K90412202
HistoryDec 08, 2016 - 12:00 a.m.

K90412202 : libarchive vulnerability CVE-2015-8932

2016-12-0800:00:00
my.f5.com
17

6 Medium

AI Score

Confidence

High

0.029 Low

EPSS

Percentile

90.8%

Security Advisory Description

The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left shift. (CVE-2015-8932)
Impact
This functionality is exposed only to authenticated administrators using the LineRate Manager GUI, CLI, or REST API, when performing a system restore with a backup file of the LineRate system that has been tampered. A successful attack may allow unauthorized modification of files.