Vulnerability Name: | CVE-2015-8837 (CCN-111903) | ||||||||||||||||||||||||
Assigned: | 2015-02-06 | ||||||||||||||||||||||||
Published: | 2015-02-06 | ||||||||||||||||||||||||
Updated: | 2020-07-27 | ||||||||||||||||||||||||
Summary: | Stack-based buffer overflow in the isofs_real_readdir function in isofs.c in FuseISO 20070708 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long pathname in an ISO file. | ||||||||||||||||||||||||
CVSS v3 Severity: | 7.3 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H) 6.4 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
5.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:U/RL:U/RC:R)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-8837 Source: DEBIAN Type: Third Party Advisory DSA-3551 Source: CCN Type: oss-sec Mailing List, Fri, 06 Feb 2015 16:17:35 -0700 older fuseiso stuff Source: MLIST Type: UNKNOWN [oss-security] 20150206 older fuseiso stuff Source: MLIST Type: UNKNOWN [oss-security] 20150223 Re: older fuseiso stuff Source: CONFIRM Type: Exploit, Issue Tracking, Patch https://bugzilla.redhat.com/show_bug.cgi?id=862211 Source: CCN Type: Red Hat Bugzilla Bug 863091 (CVE-2015-8837) CVE-2015-8837 fuseiso: Stack-based buffer overflow when scanning directory structure for absolute path entries Source: CONFIRM Type: Issue Tracking https://bugzilla.redhat.com/show_bug.cgi?id=863091 Source: XF Type: UNKNOWN fuseiso-cve20158837-bo(111903) Source: GENTOO Type: UNKNOWN GLSA-202007-20 Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-8837 | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Denotes that component is vulnerable | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |