Vulnerability Name: | CVE-2015-8836 (CCN-111899) | ||||||||||||||||||||||||
Assigned: | 2015-02-06 | ||||||||||||||||||||||||
Published: | 2015-02-06 | ||||||||||||||||||||||||
Updated: | 2017-02-19 | ||||||||||||||||||||||||
Summary: | Integer overflow in the isofs_real_read_zf function in isofs.c in FuseISO 20070708 might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a large ZF block size in an ISO file, leading to a heap-based buffer overflow. | ||||||||||||||||||||||||
CVSS v3 Severity: | 7.3 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H) 6.4 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
5.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:U/RL:U/RC:R)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-8836 Source: DEBIAN Type: Third Party Advisory DSA-3551 Source: CCN Type: oss-sec Mailing List, Fri, 06 Feb 2015 16:17:35 -0700 older fuseiso stuff Source: MLIST Type: Mailing List [oss-security] 20150206 older fuseiso stuff Source: MLIST Type: Mailing List [oss-security] 20150223 Re: older fuseiso stuff Source: CONFIRM Type: Exploit, Issue Tracking, Patch, Technical Description https://bugzilla.redhat.com/show_bug.cgi?id=861358 Source: CCN Type: Red Hat Bugzilla Bug 863102 (CVE-2015-8836) CVE-2015-8836 fuseiso: Integer overflow, leading to heap buffer overflow when reading certain ISO ZF blocks Source: CONFIRM Type: Issue Tracking https://bugzilla.redhat.com/show_bug.cgi?id=863102 Source: XF Type: UNKNOWN fuseiso-cve20158836-bo(111899) Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-8836 | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: ![]() | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |