{"cves":[{"id":"CVE-2015-8933","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:50:00.013332+00:00","description":"\nInteger overflow in the archive_read_format_tar_skip function in\narchive_read_support_format_tar.c in libarchive before 3.2.0 allows remote\nattackers to cause a denial of service (crash) via a crafted tar file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3033-1","https://www.cve.org/CVERecord?id=CVE-2015-8933"],"bugs":["https://github.com/libarchive/libarchive/issues/548"],"patches":{"libarchive":["upstream: https://github.com/libarchive/libarchive/commit/3c7a6dc6694d9b26400d2bd672e04d09ed8a4276"]},"tags":{},"packages":[{"name":"libarchive","source":"https://ubuntu.com/security/cve?package=libarchive","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libarchive","debian":"https://tracker.debian.org/pkg/libarchive","statuses":[{"release_codename":"precise","status":"released","description":"3.0.3-6ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.1.2-7ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.0-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"3.1.2-11ubuntu0.15.10.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.1.2-11ubuntu0.16.04.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3033-1"],"notices":[{"id":"USN-3033-1","title":"libarchive vulnerabilities","summary":"libarchive could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-07-14T17:55:04.967093","description":"Hanno Böck discovered that libarchive contained multiple security issues\nwhen processing certain malformed archive files. A remote attacker could\nuse this issue to cause libarchive to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2015-8916, CVE-2015-8917\nCVE-2015-8919, CVE-2015-8920, CVE-2015-8921, CVE-2015-8922, CVE-2015-8923,\nCVE-2015-8924, CVE-2015-8925, CVE-2015-8926, CVE-2015-8928, CVE-2015-8930,\nCVE-2015-8931, CVE-2015-8932, CVE-2015-8933, CVE-2015-8934, CVE-2016-5844)\n\nMarcin \"Icewall\" Noga discovered that libarchive contained multiple\nsecurity issues when processing certain malformed archive files. A remote\nattacker could use this issue to cause libarchive to crash, resulting in a\ndenial of service, or possibly execute arbitrary code. (CVE-2016-4300,\nCVE-2016-4302)\n\nIt was discovered that libarchive incorrectly handled memory allocation\nwith large cpio symlinks. A remote attacker could use this issue to\npossibly cause libarchive to crash, resulting in a denial of service.\n(CVE-2016-4809)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libarchive","version":"3.0.3-6ubuntu1.3","description":"Library to read/write archive files","is_source":true},{"name":"libarchive12","version":"3.0.3-6ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.0.3-6ubuntu1.3"}],"trusty":[{"name":"libarchive","version":"3.1.2-7ubuntu2.3","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"bsdtar","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive13","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"}],"wily":[{"name":"libarchive","version":"3.1.2-11ubuntu0.15.10.2","description":"Library to read/write archive files","is_source":true},{"name":"libarchive13","version":"3.1.2-11ubuntu0.15.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.15.10.2"}],"xenial":[{"name":"libarchive","version":"3.1.2-11ubuntu0.16.04.2","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"bsdtar","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive13","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-8916","CVE-2015-8917","CVE-2015-8919","CVE-2015-8920","CVE-2015-8921","CVE-2015-8922","CVE-2015-8923","CVE-2015-8924","CVE-2015-8925","CVE-2015-8926","CVE-2015-8928","CVE-2015-8930","CVE-2015-8931","CVE-2015-8932","CVE-2015-8933","CVE-2015-8934","CVE-2016-4300","CVE-2016-4302","CVE-2016-4809","CVE-2016-5844"]}]},{"id":"CVE-2015-8932","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:50:00.013332+00:00","description":"\nThe compress_bidder_init function in archive_read_support_filter_compress.c\nin libarchive before 3.2.0 allows remote attackers to cause a denial of\nservice (crash) via a crafted tar file, which triggers an invalid left\nshift.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3033-1","https://www.cve.org/CVERecord?id=CVE-2015-8932"],"bugs":["https://github.com/libarchive/libarchive/issues/547"],"patches":{"libarchive":["upstream: https://github.com/libarchive/libarchive/commit/f0b1dbbc325a2d922015eee402b72edd422cb9ea","upstream: https://github.com/libarchive/libarchive/commit/55ce98e829eda3a4356c2be64a778d8740c2cf6c","upstream: https://github.com/libarchive/libarchive/commit/618618c8a6be453f79e0bdbdeab6e1dd8bf429b3"]},"tags":{},"packages":[{"name":"libarchive","source":"https://ubuntu.com/security/cve?package=libarchive","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libarchive","debian":"https://tracker.debian.org/pkg/libarchive","statuses":[{"release_codename":"precise","status":"released","description":"3.0.3-6ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.1.2-7ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.0-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"3.1.2-11ubuntu0.15.10.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.1.2-11ubuntu0.16.04.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3033-1"],"notices":[{"id":"USN-3033-1","title":"libarchive vulnerabilities","summary":"libarchive could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-07-14T17:55:04.967093","description":"Hanno Böck discovered that libarchive contained multiple security issues\nwhen processing certain malformed archive files. A remote attacker could\nuse this issue to cause libarchive to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2015-8916, CVE-2015-8917\nCVE-2015-8919, CVE-2015-8920, CVE-2015-8921, CVE-2015-8922, CVE-2015-8923,\nCVE-2015-8924, CVE-2015-8925, CVE-2015-8926, CVE-2015-8928, CVE-2015-8930,\nCVE-2015-8931, CVE-2015-8932, CVE-2015-8933, CVE-2015-8934, CVE-2016-5844)\n\nMarcin \"Icewall\" Noga discovered that libarchive contained multiple\nsecurity issues when processing certain malformed archive files. A remote\nattacker could use this issue to cause libarchive to crash, resulting in a\ndenial of service, or possibly execute arbitrary code. (CVE-2016-4300,\nCVE-2016-4302)\n\nIt was discovered that libarchive incorrectly handled memory allocation\nwith large cpio symlinks. A remote attacker could use this issue to\npossibly cause libarchive to crash, resulting in a denial of service.\n(CVE-2016-4809)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libarchive","version":"3.0.3-6ubuntu1.3","description":"Library to read/write archive files","is_source":true},{"name":"libarchive12","version":"3.0.3-6ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.0.3-6ubuntu1.3"}],"trusty":[{"name":"libarchive","version":"3.1.2-7ubuntu2.3","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"bsdtar","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive13","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"}],"wily":[{"name":"libarchive","version":"3.1.2-11ubuntu0.15.10.2","description":"Library to read/write archive files","is_source":true},{"name":"libarchive13","version":"3.1.2-11ubuntu0.15.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.15.10.2"}],"xenial":[{"name":"libarchive","version":"3.1.2-11ubuntu0.16.04.2","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"bsdtar","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive13","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-8916","CVE-2015-8917","CVE-2015-8919","CVE-2015-8920","CVE-2015-8921","CVE-2015-8922","CVE-2015-8923","CVE-2015-8924","CVE-2015-8925","CVE-2015-8926","CVE-2015-8928","CVE-2015-8930","CVE-2015-8931","CVE-2015-8932","CVE-2015-8933","CVE-2015-8934","CVE-2016-4300","CVE-2016-4302","CVE-2016-4809","CVE-2016-5844"]}]},{"id":"CVE-2015-8931","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:50:00.013332+00:00","description":"\nMultiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min\nfunctions in archive_read_support_format_mtree.c in libarchive before 3.2.0\nallow remote attackers to have unspecified impact via a crafted mtree file,\nwhich triggers undefined behavior.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3033-1","https://www.cve.org/CVERecord?id=CVE-2015-8931"],"bugs":["https://github.com/libarchive/libarchive/issues/539"],"patches":{"libarchive":["upstream: https://github.com/libarchive/libarchive/commit/b31744df71084a8734f97199e42418f55d08c6c5","upstream: https://github.com/libarchive/libarchive/commit/c0c52e9aaafb0860c4151c5374372051e9354301"]},"tags":{},"packages":[{"name":"libarchive","source":"https://ubuntu.com/security/cve?package=libarchive","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libarchive","debian":"https://tracker.debian.org/pkg/libarchive","statuses":[{"release_codename":"precise","status":"released","description":"3.0.3-6ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.1.2-7ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.0-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"3.1.2-11ubuntu0.15.10.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.1.2-11ubuntu0.16.04.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3033-1"],"notices":[{"id":"USN-3033-1","title":"libarchive vulnerabilities","summary":"libarchive could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-07-14T17:55:04.967093","description":"Hanno Böck discovered that libarchive contained multiple security issues\nwhen processing certain malformed archive files. A remote attacker could\nuse this issue to cause libarchive to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2015-8916, CVE-2015-8917\nCVE-2015-8919, CVE-2015-8920, CVE-2015-8921, CVE-2015-8922, CVE-2015-8923,\nCVE-2015-8924, CVE-2015-8925, CVE-2015-8926, CVE-2015-8928, CVE-2015-8930,\nCVE-2015-8931, CVE-2015-8932, CVE-2015-8933, CVE-2015-8934, CVE-2016-5844)\n\nMarcin \"Icewall\" Noga discovered that libarchive contained multiple\nsecurity issues when processing certain malformed archive files. A remote\nattacker could use this issue to cause libarchive to crash, resulting in a\ndenial of service, or possibly execute arbitrary code. (CVE-2016-4300,\nCVE-2016-4302)\n\nIt was discovered that libarchive incorrectly handled memory allocation\nwith large cpio symlinks. A remote attacker could use this issue to\npossibly cause libarchive to crash, resulting in a denial of service.\n(CVE-2016-4809)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libarchive","version":"3.0.3-6ubuntu1.3","description":"Library to read/write archive files","is_source":true},{"name":"libarchive12","version":"3.0.3-6ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.0.3-6ubuntu1.3"}],"trusty":[{"name":"libarchive","version":"3.1.2-7ubuntu2.3","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"bsdtar","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive13","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"}],"wily":[{"name":"libarchive","version":"3.1.2-11ubuntu0.15.10.2","description":"Library to read/write archive files","is_source":true},{"name":"libarchive13","version":"3.1.2-11ubuntu0.15.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.15.10.2"}],"xenial":[{"name":"libarchive","version":"3.1.2-11ubuntu0.16.04.2","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"bsdtar","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive13","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-8916","CVE-2015-8917","CVE-2015-8919","CVE-2015-8920","CVE-2015-8921","CVE-2015-8922","CVE-2015-8923","CVE-2015-8924","CVE-2015-8925","CVE-2015-8926","CVE-2015-8928","CVE-2015-8930","CVE-2015-8931","CVE-2015-8932","CVE-2015-8933","CVE-2015-8934","CVE-2016-4300","CVE-2016-4302","CVE-2016-4809","CVE-2016-5844"]}]},{"id":"CVE-2015-8930","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:50:00.013332+00:00","description":"\nbsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial\nof service (infinite loop) via an ISO with a directory that is a member of\nitself.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3033-1","https://www.cve.org/CVERecord?id=CVE-2015-8930"],"bugs":["https://github.com/libarchive/libarchive/issues/522"],"patches":{"libarchive":["upstream: https://github.com/libarchive/libarchive/commit/39fc59391b7cf2a007bffce280c1e3e66674258f","upstream: https://github.com/libarchive/libarchive/commit/01cfbca4fdae1492a8a09c001b61bbca46f869f2"]},"tags":{},"packages":[{"name":"libarchive","source":"https://ubuntu.com/security/cve?package=libarchive","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libarchive","debian":"https://tracker.debian.org/pkg/libarchive","statuses":[{"release_codename":"precise","status":"released","description":"3.0.3-6ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.1.2-7ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.0-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"3.1.2-11ubuntu0.15.10.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.1.2-11ubuntu0.16.04.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3033-1"],"notices":[{"id":"USN-3033-1","title":"libarchive vulnerabilities","summary":"libarchive could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-07-14T17:55:04.967093","description":"Hanno Böck discovered that libarchive contained multiple security issues\nwhen processing certain malformed archive files. A remote attacker could\nuse this issue to cause libarchive to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2015-8916, CVE-2015-8917\nCVE-2015-8919, CVE-2015-8920, CVE-2015-8921, CVE-2015-8922, CVE-2015-8923,\nCVE-2015-8924, CVE-2015-8925, CVE-2015-8926, CVE-2015-8928, CVE-2015-8930,\nCVE-2015-8931, CVE-2015-8932, CVE-2015-8933, CVE-2015-8934, CVE-2016-5844)\n\nMarcin \"Icewall\" Noga discovered that libarchive contained multiple\nsecurity issues when processing certain malformed archive files. A remote\nattacker could use this issue to cause libarchive to crash, resulting in a\ndenial of service, or possibly execute arbitrary code. (CVE-2016-4300,\nCVE-2016-4302)\n\nIt was discovered that libarchive incorrectly handled memory allocation\nwith large cpio symlinks. A remote attacker could use this issue to\npossibly cause libarchive to crash, resulting in a denial of service.\n(CVE-2016-4809)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libarchive","version":"3.0.3-6ubuntu1.3","description":"Library to read/write archive files","is_source":true},{"name":"libarchive12","version":"3.0.3-6ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.0.3-6ubuntu1.3"}],"trusty":[{"name":"libarchive","version":"3.1.2-7ubuntu2.3","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"bsdtar","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive13","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"}],"wily":[{"name":"libarchive","version":"3.1.2-11ubuntu0.15.10.2","description":"Library to read/write archive files","is_source":true},{"name":"libarchive13","version":"3.1.2-11ubuntu0.15.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.15.10.2"}],"xenial":[{"name":"libarchive","version":"3.1.2-11ubuntu0.16.04.2","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"bsdtar","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive13","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-8916","CVE-2015-8917","CVE-2015-8919","CVE-2015-8920","CVE-2015-8921","CVE-2015-8922","CVE-2015-8923","CVE-2015-8924","CVE-2015-8925","CVE-2015-8926","CVE-2015-8928","CVE-2015-8930","CVE-2015-8931","CVE-2015-8932","CVE-2015-8933","CVE-2015-8934","CVE-2016-4300","CVE-2016-4302","CVE-2016-4809","CVE-2016-5844"]}]},{"id":"CVE-2015-8928","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:49:55.529862+00:00","description":"\nThe process_add_entry function in archive_read_support_format_mtree.c in\nlibarchive before 3.2.0 allows remote attackers to cause a denial of\nservice (out-of-bounds read) via a crafted mtree file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3033-1","https://www.cve.org/CVERecord?id=CVE-2015-8928"],"bugs":["https://github.com/libarchive/libarchive/issues/550"],"patches":{"libarchive":["upstream: https://github.com/libarchive/libarchive/commit/64d5628"]},"tags":{},"packages":[{"name":"libarchive","source":"https://ubuntu.com/security/cve?package=libarchive","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libarchive","debian":"https://tracker.debian.org/pkg/libarchive","statuses":[{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.1.2-7ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.0-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"3.1.2-11ubuntu0.15.10.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.1.2-11ubuntu0.16.04.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3033-1"],"notices":[{"id":"USN-3033-1","title":"libarchive vulnerabilities","summary":"libarchive could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-07-14T17:55:04.967093","description":"Hanno Böck discovered that libarchive contained multiple security issues\nwhen processing certain malformed archive files. A remote attacker could\nuse this issue to cause libarchive to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2015-8916, CVE-2015-8917\nCVE-2015-8919, CVE-2015-8920, CVE-2015-8921, CVE-2015-8922, CVE-2015-8923,\nCVE-2015-8924, CVE-2015-8925, CVE-2015-8926, CVE-2015-8928, CVE-2015-8930,\nCVE-2015-8931, CVE-2015-8932, CVE-2015-8933, CVE-2015-8934, CVE-2016-5844)\n\nMarcin \"Icewall\" Noga discovered that libarchive contained multiple\nsecurity issues when processing certain malformed archive files. A remote\nattacker could use this issue to cause libarchive to crash, resulting in a\ndenial of service, or possibly execute arbitrary code. (CVE-2016-4300,\nCVE-2016-4302)\n\nIt was discovered that libarchive incorrectly handled memory allocation\nwith large cpio symlinks. A remote attacker could use this issue to\npossibly cause libarchive to crash, resulting in a denial of service.\n(CVE-2016-4809)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libarchive","version":"3.0.3-6ubuntu1.3","description":"Library to read/write archive files","is_source":true},{"name":"libarchive12","version":"3.0.3-6ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.0.3-6ubuntu1.3"}],"trusty":[{"name":"libarchive","version":"3.1.2-7ubuntu2.3","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"bsdtar","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive13","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"}],"wily":[{"name":"libarchive","version":"3.1.2-11ubuntu0.15.10.2","description":"Library to read/write archive files","is_source":true},{"name":"libarchive13","version":"3.1.2-11ubuntu0.15.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.15.10.2"}],"xenial":[{"name":"libarchive","version":"3.1.2-11ubuntu0.16.04.2","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"bsdtar","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive13","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-8916","CVE-2015-8917","CVE-2015-8919","CVE-2015-8920","CVE-2015-8921","CVE-2015-8922","CVE-2015-8923","CVE-2015-8924","CVE-2015-8925","CVE-2015-8926","CVE-2015-8928","CVE-2015-8930","CVE-2015-8931","CVE-2015-8932","CVE-2015-8933","CVE-2015-8934","CVE-2016-4300","CVE-2016-4302","CVE-2016-4809","CVE-2016-5844"]}]},{"id":"CVE-2015-8926","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:49:55.529862+00:00","description":"\nThe archive_read_format_rar_read_data function in\narchive_read_support_format_rar.c in libarchive before 3.2.0 allows remote\nattackers to cause a denial of service (crash) via a crafted rar archive.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3033-1","https://www.cve.org/CVERecord?id=CVE-2015-8926"],"bugs":["https://github.com/libarchive/libarchive/issues/518"],"patches":{"libarchive":["upstream: https://github.com/libarchive/libarchive/commit/aab73938"]},"tags":{},"packages":[{"name":"libarchive","source":"https://ubuntu.com/security/cve?package=libarchive","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libarchive","debian":"https://tracker.debian.org/pkg/libarchive","statuses":[{"release_codename":"precise","status":"released","description":"3.0.3-6ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.1.2-7ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.0-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"3.1.2-11ubuntu0.15.10.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.1.2-11ubuntu0.16.04.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3033-1"],"notices":[{"id":"USN-3033-1","title":"libarchive vulnerabilities","summary":"libarchive could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-07-14T17:55:04.967093","description":"Hanno Böck discovered that libarchive contained multiple security issues\nwhen processing certain malformed archive files. A remote attacker could\nuse this issue to cause libarchive to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2015-8916, CVE-2015-8917\nCVE-2015-8919, CVE-2015-8920, CVE-2015-8921, CVE-2015-8922, CVE-2015-8923,\nCVE-2015-8924, CVE-2015-8925, CVE-2015-8926, CVE-2015-8928, CVE-2015-8930,\nCVE-2015-8931, CVE-2015-8932, CVE-2015-8933, CVE-2015-8934, CVE-2016-5844)\n\nMarcin \"Icewall\" Noga discovered that libarchive contained multiple\nsecurity issues when processing certain malformed archive files. A remote\nattacker could use this issue to cause libarchive to crash, resulting in a\ndenial of service, or possibly execute arbitrary code. (CVE-2016-4300,\nCVE-2016-4302)\n\nIt was discovered that libarchive incorrectly handled memory allocation\nwith large cpio symlinks. A remote attacker could use this issue to\npossibly cause libarchive to crash, resulting in a denial of service.\n(CVE-2016-4809)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libarchive","version":"3.0.3-6ubuntu1.3","description":"Library to read/write archive files","is_source":true},{"name":"libarchive12","version":"3.0.3-6ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.0.3-6ubuntu1.3"}],"trusty":[{"name":"libarchive","version":"3.1.2-7ubuntu2.3","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"bsdtar","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive13","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"}],"wily":[{"name":"libarchive","version":"3.1.2-11ubuntu0.15.10.2","description":"Library to read/write archive files","is_source":true},{"name":"libarchive13","version":"3.1.2-11ubuntu0.15.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.15.10.2"}],"xenial":[{"name":"libarchive","version":"3.1.2-11ubuntu0.16.04.2","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"bsdtar","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive13","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-8916","CVE-2015-8917","CVE-2015-8919","CVE-2015-8920","CVE-2015-8921","CVE-2015-8922","CVE-2015-8923","CVE-2015-8924","CVE-2015-8925","CVE-2015-8926","CVE-2015-8928","CVE-2015-8930","CVE-2015-8931","CVE-2015-8932","CVE-2015-8933","CVE-2015-8934","CVE-2016-4300","CVE-2016-4302","CVE-2016-4809","CVE-2016-5844"]}]},{"id":"CVE-2015-8925","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:49:55.529862+00:00","description":"\nThe readline function in archive_read_support_format_mtree.c in libarchive\nbefore 3.2.0 allows remote attackers to cause a denial of service (invalid\nread) via a crafted mtree file, related to newline parsing.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3033-1","https://www.cve.org/CVERecord?id=CVE-2015-8925"],"bugs":["https://github.com/libarchive/libarchive/issues/516"],"patches":{"libarchive":["upstream: https://github.com/libarchive/libarchive/commit/1e18cbb71"]},"tags":{},"packages":[{"name":"libarchive","source":"https://ubuntu.com/security/cve?package=libarchive","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libarchive","debian":"https://tracker.debian.org/pkg/libarchive","statuses":[{"release_codename":"precise","status":"released","description":"3.0.3-6ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.1.2-7ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.0-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"3.1.2-11ubuntu0.15.10.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.1.2-11ubuntu0.16.04.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3033-1"],"notices":[{"id":"USN-3033-1","title":"libarchive vulnerabilities","summary":"libarchive could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-07-14T17:55:04.967093","description":"Hanno Böck discovered that libarchive contained multiple security issues\nwhen processing certain malformed archive files. A remote attacker could\nuse this issue to cause libarchive to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2015-8916, CVE-2015-8917\nCVE-2015-8919, CVE-2015-8920, CVE-2015-8921, CVE-2015-8922, CVE-2015-8923,\nCVE-2015-8924, CVE-2015-8925, CVE-2015-8926, CVE-2015-8928, CVE-2015-8930,\nCVE-2015-8931, CVE-2015-8932, CVE-2015-8933, CVE-2015-8934, CVE-2016-5844)\n\nMarcin \"Icewall\" Noga discovered that libarchive contained multiple\nsecurity issues when processing certain malformed archive files. A remote\nattacker could use this issue to cause libarchive to crash, resulting in a\ndenial of service, or possibly execute arbitrary code. (CVE-2016-4300,\nCVE-2016-4302)\n\nIt was discovered that libarchive incorrectly handled memory allocation\nwith large cpio symlinks. A remote attacker could use this issue to\npossibly cause libarchive to crash, resulting in a denial of service.\n(CVE-2016-4809)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libarchive","version":"3.0.3-6ubuntu1.3","description":"Library to read/write archive files","is_source":true},{"name":"libarchive12","version":"3.0.3-6ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.0.3-6ubuntu1.3"}],"trusty":[{"name":"libarchive","version":"3.1.2-7ubuntu2.3","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"bsdtar","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive13","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"}],"wily":[{"name":"libarchive","version":"3.1.2-11ubuntu0.15.10.2","description":"Library to read/write archive files","is_source":true},{"name":"libarchive13","version":"3.1.2-11ubuntu0.15.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.15.10.2"}],"xenial":[{"name":"libarchive","version":"3.1.2-11ubuntu0.16.04.2","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"bsdtar","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive13","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-8916","CVE-2015-8917","CVE-2015-8919","CVE-2015-8920","CVE-2015-8921","CVE-2015-8922","CVE-2015-8923","CVE-2015-8924","CVE-2015-8925","CVE-2015-8926","CVE-2015-8928","CVE-2015-8930","CVE-2015-8931","CVE-2015-8932","CVE-2015-8933","CVE-2015-8934","CVE-2016-4300","CVE-2016-4302","CVE-2016-4809","CVE-2016-5844"]}]},{"id":"CVE-2015-8924","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:49:55.529862+00:00","description":"\nThe archive_read_format_tar_read_header function in\narchive_read_support_format_tar.c in libarchive before 3.2.0 allows remote\nattackers to cause a denial of service (out-of-bounds read) via a crafted\ntar file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3033-1","https://www.cve.org/CVERecord?id=CVE-2015-8924"],"bugs":["https://github.com/libarchive/libarchive/issues/515"],"patches":{"libarchive":["upstream: https://github.com/libarchive/libarchive/commit/bb9b157"]},"tags":{},"packages":[{"name":"libarchive","source":"https://ubuntu.com/security/cve?package=libarchive","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libarchive","debian":"https://tracker.debian.org/pkg/libarchive","statuses":[{"release_codename":"precise","status":"released","description":"3.0.3-6ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.1.2-7ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.0-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"3.1.2-11ubuntu0.15.10.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.1.2-11ubuntu0.16.04.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3033-1"],"notices":[{"id":"USN-3033-1","title":"libarchive vulnerabilities","summary":"libarchive could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-07-14T17:55:04.967093","description":"Hanno Böck discovered that libarchive contained multiple security issues\nwhen processing certain malformed archive files. A remote attacker could\nuse this issue to cause libarchive to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2015-8916, CVE-2015-8917\nCVE-2015-8919, CVE-2015-8920, CVE-2015-8921, CVE-2015-8922, CVE-2015-8923,\nCVE-2015-8924, CVE-2015-8925, CVE-2015-8926, CVE-2015-8928, CVE-2015-8930,\nCVE-2015-8931, CVE-2015-8932, CVE-2015-8933, CVE-2015-8934, CVE-2016-5844)\n\nMarcin \"Icewall\" Noga discovered that libarchive contained multiple\nsecurity issues when processing certain malformed archive files. A remote\nattacker could use this issue to cause libarchive to crash, resulting in a\ndenial of service, or possibly execute arbitrary code. (CVE-2016-4300,\nCVE-2016-4302)\n\nIt was discovered that libarchive incorrectly handled memory allocation\nwith large cpio symlinks. A remote attacker could use this issue to\npossibly cause libarchive to crash, resulting in a denial of service.\n(CVE-2016-4809)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libarchive","version":"3.0.3-6ubuntu1.3","description":"Library to read/write archive files","is_source":true},{"name":"libarchive12","version":"3.0.3-6ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.0.3-6ubuntu1.3"}],"trusty":[{"name":"libarchive","version":"3.1.2-7ubuntu2.3","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"bsdtar","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive13","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"}],"wily":[{"name":"libarchive","version":"3.1.2-11ubuntu0.15.10.2","description":"Library to read/write archive files","is_source":true},{"name":"libarchive13","version":"3.1.2-11ubuntu0.15.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.15.10.2"}],"xenial":[{"name":"libarchive","version":"3.1.2-11ubuntu0.16.04.2","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"bsdtar","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive13","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-8916","CVE-2015-8917","CVE-2015-8919","CVE-2015-8920","CVE-2015-8921","CVE-2015-8922","CVE-2015-8923","CVE-2015-8924","CVE-2015-8925","CVE-2015-8926","CVE-2015-8928","CVE-2015-8930","CVE-2015-8931","CVE-2015-8932","CVE-2015-8933","CVE-2015-8934","CVE-2016-4300","CVE-2016-4302","CVE-2016-4809","CVE-2016-5844"]}]},{"id":"CVE-2015-8923","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:49:55.529862+00:00","description":"\nThe process_extra function in libarchive before 3.2.0 uses the size field\nand a signed number in an offset, which allows remote attackers to cause a\ndenial of service (crash) via a crafted zip file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3033-1","https://www.cve.org/CVERecord?id=CVE-2015-8923"],"bugs":["https://github.com/libarchive/libarchive/issues/514"],"patches":{"libarchive":["upstream: https://github.com/libarchive/libarchive/commit/9e0689c"]},"tags":{},"packages":[{"name":"libarchive","source":"https://ubuntu.com/security/cve?package=libarchive","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libarchive","debian":"https://tracker.debian.org/pkg/libarchive","statuses":[{"release_codename":"precise","status":"released","description":"3.0.3-6ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.1.2-7ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.0-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"3.1.2-11ubuntu0.15.10.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.1.2-11ubuntu0.16.04.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3033-1"],"notices":[{"id":"USN-3033-1","title":"libarchive vulnerabilities","summary":"libarchive could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-07-14T17:55:04.967093","description":"Hanno Böck discovered that libarchive contained multiple security issues\nwhen processing certain malformed archive files. A remote attacker could\nuse this issue to cause libarchive to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2015-8916, CVE-2015-8917\nCVE-2015-8919, CVE-2015-8920, CVE-2015-8921, CVE-2015-8922, CVE-2015-8923,\nCVE-2015-8924, CVE-2015-8925, CVE-2015-8926, CVE-2015-8928, CVE-2015-8930,\nCVE-2015-8931, CVE-2015-8932, CVE-2015-8933, CVE-2015-8934, CVE-2016-5844)\n\nMarcin \"Icewall\" Noga discovered that libarchive contained multiple\nsecurity issues when processing certain malformed archive files. A remote\nattacker could use this issue to cause libarchive to crash, resulting in a\ndenial of service, or possibly execute arbitrary code. (CVE-2016-4300,\nCVE-2016-4302)\n\nIt was discovered that libarchive incorrectly handled memory allocation\nwith large cpio symlinks. A remote attacker could use this issue to\npossibly cause libarchive to crash, resulting in a denial of service.\n(CVE-2016-4809)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libarchive","version":"3.0.3-6ubuntu1.3","description":"Library to read/write archive files","is_source":true},{"name":"libarchive12","version":"3.0.3-6ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.0.3-6ubuntu1.3"}],"trusty":[{"name":"libarchive","version":"3.1.2-7ubuntu2.3","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"bsdtar","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive13","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"}],"wily":[{"name":"libarchive","version":"3.1.2-11ubuntu0.15.10.2","description":"Library to read/write archive files","is_source":true},{"name":"libarchive13","version":"3.1.2-11ubuntu0.15.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.15.10.2"}],"xenial":[{"name":"libarchive","version":"3.1.2-11ubuntu0.16.04.2","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"bsdtar","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive13","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-8916","CVE-2015-8917","CVE-2015-8919","CVE-2015-8920","CVE-2015-8921","CVE-2015-8922","CVE-2015-8923","CVE-2015-8924","CVE-2015-8925","CVE-2015-8926","CVE-2015-8928","CVE-2015-8930","CVE-2015-8931","CVE-2015-8932","CVE-2015-8933","CVE-2015-8934","CVE-2016-4300","CVE-2016-4302","CVE-2016-4809","CVE-2016-5844"]}]},{"id":"CVE-2015-8922","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:49:55.529862+00:00","description":"\nThe read_CodersInfo function in archive_read_support_format_7zip.c in\nlibarchive before 3.2.0 allows remote attackers to cause a denial of\nservice (NULL pointer dereference and crash) via a crafted 7z file, related\nto the _7z_folder struct.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3033-1","https://www.cve.org/CVERecord?id=CVE-2015-8922"],"bugs":["https://github.com/libarchive/libarchive/issues/513"],"patches":{"libarchive":["upstream: https://github.com/libarchive/libarchive/commit/d094dc"]},"tags":{},"packages":[{"name":"libarchive","source":"https://ubuntu.com/security/cve?package=libarchive","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libarchive","debian":"https://tracker.debian.org/pkg/libarchive","statuses":[{"release_codename":"precise","status":"released","description":"3.0.3-6ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.1.2-7ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.0-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"3.1.2-11ubuntu0.15.10.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.1.2-11ubuntu0.16.04.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3033-1"],"notices":[{"id":"USN-3033-1","title":"libarchive vulnerabilities","summary":"libarchive could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-07-14T17:55:04.967093","description":"Hanno Böck discovered that libarchive contained multiple security issues\nwhen processing certain malformed archive files. A remote attacker could\nuse this issue to cause libarchive to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2015-8916, CVE-2015-8917\nCVE-2015-8919, CVE-2015-8920, CVE-2015-8921, CVE-2015-8922, CVE-2015-8923,\nCVE-2015-8924, CVE-2015-8925, CVE-2015-8926, CVE-2015-8928, CVE-2015-8930,\nCVE-2015-8931, CVE-2015-8932, CVE-2015-8933, CVE-2015-8934, CVE-2016-5844)\n\nMarcin \"Icewall\" Noga discovered that libarchive contained multiple\nsecurity issues when processing certain malformed archive files. A remote\nattacker could use this issue to cause libarchive to crash, resulting in a\ndenial of service, or possibly execute arbitrary code. (CVE-2016-4300,\nCVE-2016-4302)\n\nIt was discovered that libarchive incorrectly handled memory allocation\nwith large cpio symlinks. A remote attacker could use this issue to\npossibly cause libarchive to crash, resulting in a denial of service.\n(CVE-2016-4809)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libarchive","version":"3.0.3-6ubuntu1.3","description":"Library to read/write archive files","is_source":true},{"name":"libarchive12","version":"3.0.3-6ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.0.3-6ubuntu1.3"}],"trusty":[{"name":"libarchive","version":"3.1.2-7ubuntu2.3","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"bsdtar","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive13","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"}],"wily":[{"name":"libarchive","version":"3.1.2-11ubuntu0.15.10.2","description":"Library to read/write archive files","is_source":true},{"name":"libarchive13","version":"3.1.2-11ubuntu0.15.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.15.10.2"}],"xenial":[{"name":"libarchive","version":"3.1.2-11ubuntu0.16.04.2","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"bsdtar","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive13","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-8916","CVE-2015-8917","CVE-2015-8919","CVE-2015-8920","CVE-2015-8921","CVE-2015-8922","CVE-2015-8923","CVE-2015-8924","CVE-2015-8925","CVE-2015-8926","CVE-2015-8928","CVE-2015-8930","CVE-2015-8931","CVE-2015-8932","CVE-2015-8933","CVE-2015-8934","CVE-2016-4300","CVE-2016-4302","CVE-2016-4809","CVE-2016-5844"]}]},{"id":"CVE-2015-8921","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:49:55.529862+00:00","description":"\nThe ae_strtofflags function in archive_entry.c in libarchive before 3.2.0\nallows remote attackers to cause a denial of service (out-of-bounds read)\nvia a crafted mtree file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3033-1","https://www.cve.org/CVERecord?id=CVE-2015-8921"],"bugs":["https://github.com/libarchive/libarchive/issues/512"],"patches":{"libarchive":["upstream: https://github.com/libarchive/libarchive/commit/1cbc76faffb79a99c6009a1816736f73b4a3632a","upstream: https://github.com/libarchive/libarchive/commit/05a875fdb876e7a2f56a2937f756927cbed919e0","upstream: https://github.com/libarchive/libarchive/commit/90632371f89d1390bf71dd31ae1c842b9110bea2","upstream: https://github.com/libarchive/libarchive/commit/c600d11f2c1645f6f6965592659d386436f4d6db"]},"tags":{},"packages":[{"name":"libarchive","source":"https://ubuntu.com/security/cve?package=libarchive","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libarchive","debian":"https://tracker.debian.org/pkg/libarchive","statuses":[{"release_codename":"precise","status":"released","description":"3.0.3-6ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.1.2-7ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.0-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"3.1.2-11ubuntu0.15.10.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.1.2-11ubuntu0.16.04.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3033-1"],"notices":[{"id":"USN-3033-1","title":"libarchive vulnerabilities","summary":"libarchive could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-07-14T17:55:04.967093","description":"Hanno Böck discovered that libarchive contained multiple security issues\nwhen processing certain malformed archive files. A remote attacker could\nuse this issue to cause libarchive to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2015-8916, CVE-2015-8917\nCVE-2015-8919, CVE-2015-8920, CVE-2015-8921, CVE-2015-8922, CVE-2015-8923,\nCVE-2015-8924, CVE-2015-8925, CVE-2015-8926, CVE-2015-8928, CVE-2015-8930,\nCVE-2015-8931, CVE-2015-8932, CVE-2015-8933, CVE-2015-8934, CVE-2016-5844)\n\nMarcin \"Icewall\" Noga discovered that libarchive contained multiple\nsecurity issues when processing certain malformed archive files. A remote\nattacker could use this issue to cause libarchive to crash, resulting in a\ndenial of service, or possibly execute arbitrary code. (CVE-2016-4300,\nCVE-2016-4302)\n\nIt was discovered that libarchive incorrectly handled memory allocation\nwith large cpio symlinks. A remote attacker could use this issue to\npossibly cause libarchive to crash, resulting in a denial of service.\n(CVE-2016-4809)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libarchive","version":"3.0.3-6ubuntu1.3","description":"Library to read/write archive files","is_source":true},{"name":"libarchive12","version":"3.0.3-6ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.0.3-6ubuntu1.3"}],"trusty":[{"name":"libarchive","version":"3.1.2-7ubuntu2.3","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"bsdtar","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive13","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"}],"wily":[{"name":"libarchive","version":"3.1.2-11ubuntu0.15.10.2","description":"Library to read/write archive files","is_source":true},{"name":"libarchive13","version":"3.1.2-11ubuntu0.15.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.15.10.2"}],"xenial":[{"name":"libarchive","version":"3.1.2-11ubuntu0.16.04.2","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"bsdtar","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive13","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-8916","CVE-2015-8917","CVE-2015-8919","CVE-2015-8920","CVE-2015-8921","CVE-2015-8922","CVE-2015-8923","CVE-2015-8924","CVE-2015-8925","CVE-2015-8926","CVE-2015-8928","CVE-2015-8930","CVE-2015-8931","CVE-2015-8932","CVE-2015-8933","CVE-2015-8934","CVE-2016-4300","CVE-2016-4302","CVE-2016-4809","CVE-2016-5844"]}]},{"id":"CVE-2015-8920","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:49:55.529862+00:00","description":"\nThe _ar_read_header function in archive_read_support_format_ar.c in\nlibarchive before 3.2.0 allows remote attackers to cause a denial of\nservice (out-of-bounds stack read) via a crafted ar file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3033-1","https://www.cve.org/CVERecord?id=CVE-2015-8920"],"bugs":["https://github.com/libarchive/libarchive/issues/511"],"patches":{"libarchive":["upstream: https://github.com/libarchive/libarchive/commit/97f964e"]},"tags":{},"packages":[{"name":"libarchive","source":"https://ubuntu.com/security/cve?package=libarchive","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libarchive","debian":"https://tracker.debian.org/pkg/libarchive","statuses":[{"release_codename":"precise","status":"released","description":"3.0.3-6ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.1.2-7ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.0-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"3.1.2-11ubuntu0.15.10.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.1.2-11ubuntu0.16.04.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3033-1"],"notices":[{"id":"USN-3033-1","title":"libarchive vulnerabilities","summary":"libarchive could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-07-14T17:55:04.967093","description":"Hanno Böck discovered that libarchive contained multiple security issues\nwhen processing certain malformed archive files. A remote attacker could\nuse this issue to cause libarchive to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2015-8916, CVE-2015-8917\nCVE-2015-8919, CVE-2015-8920, CVE-2015-8921, CVE-2015-8922, CVE-2015-8923,\nCVE-2015-8924, CVE-2015-8925, CVE-2015-8926, CVE-2015-8928, CVE-2015-8930,\nCVE-2015-8931, CVE-2015-8932, CVE-2015-8933, CVE-2015-8934, CVE-2016-5844)\n\nMarcin \"Icewall\" Noga discovered that libarchive contained multiple\nsecurity issues when processing certain malformed archive files. A remote\nattacker could use this issue to cause libarchive to crash, resulting in a\ndenial of service, or possibly execute arbitrary code. (CVE-2016-4300,\nCVE-2016-4302)\n\nIt was discovered that libarchive incorrectly handled memory allocation\nwith large cpio symlinks. A remote attacker could use this issue to\npossibly cause libarchive to crash, resulting in a denial of service.\n(CVE-2016-4809)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libarchive","version":"3.0.3-6ubuntu1.3","description":"Library to read/write archive files","is_source":true},{"name":"libarchive12","version":"3.0.3-6ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.0.3-6ubuntu1.3"}],"trusty":[{"name":"libarchive","version":"3.1.2-7ubuntu2.3","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"bsdtar","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive13","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"}],"wily":[{"name":"libarchive","version":"3.1.2-11ubuntu0.15.10.2","description":"Library to read/write archive files","is_source":true},{"name":"libarchive13","version":"3.1.2-11ubuntu0.15.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.15.10.2"}],"xenial":[{"name":"libarchive","version":"3.1.2-11ubuntu0.16.04.2","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"bsdtar","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive13","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-8916","CVE-2015-8917","CVE-2015-8919","CVE-2015-8920","CVE-2015-8921","CVE-2015-8922","CVE-2015-8923","CVE-2015-8924","CVE-2015-8925","CVE-2015-8926","CVE-2015-8928","CVE-2015-8930","CVE-2015-8931","CVE-2015-8932","CVE-2015-8933","CVE-2015-8934","CVE-2016-4300","CVE-2016-4302","CVE-2016-4809","CVE-2016-5844"]}]},{"id":"CVE-2015-8919","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:49:55.529862+00:00","description":"\nThe lha_read_file_extended_header function in\narchive_read_support_format_lha.c in libarchive before 3.2.0 allows remote\nattackers to cause a denial of service (out-of-bounds heap) via a crafted\n(1) lzh or (2) lha file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3033-1","https://www.cve.org/CVERecord?id=CVE-2015-8919"],"bugs":["https://github.com/libarchive/libarchive/issues/510"],"patches":{"libarchive":["upstream: https://github.com/libarchive/libarchive/commit/e8a2e4d"]},"tags":{},"packages":[{"name":"libarchive","source":"https://ubuntu.com/security/cve?package=libarchive","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libarchive","debian":"https://tracker.debian.org/pkg/libarchive","statuses":[{"release_codename":"precise","status":"released","description":"3.0.3-6ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.1.2-7ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.0-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"3.1.2-11ubuntu0.15.10.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.1.2-11ubuntu0.16.04.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3033-1"],"notices":[{"id":"USN-3033-1","title":"libarchive vulnerabilities","summary":"libarchive could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-07-14T17:55:04.967093","description":"Hanno Böck discovered that libarchive contained multiple security issues\nwhen processing certain malformed archive files. A remote attacker could\nuse this issue to cause libarchive to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2015-8916, CVE-2015-8917\nCVE-2015-8919, CVE-2015-8920, CVE-2015-8921, CVE-2015-8922, CVE-2015-8923,\nCVE-2015-8924, CVE-2015-8925, CVE-2015-8926, CVE-2015-8928, CVE-2015-8930,\nCVE-2015-8931, CVE-2015-8932, CVE-2015-8933, CVE-2015-8934, CVE-2016-5844)\n\nMarcin \"Icewall\" Noga discovered that libarchive contained multiple\nsecurity issues when processing certain malformed archive files. A remote\nattacker could use this issue to cause libarchive to crash, resulting in a\ndenial of service, or possibly execute arbitrary code. (CVE-2016-4300,\nCVE-2016-4302)\n\nIt was discovered that libarchive incorrectly handled memory allocation\nwith large cpio symlinks. A remote attacker could use this issue to\npossibly cause libarchive to crash, resulting in a denial of service.\n(CVE-2016-4809)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libarchive","version":"3.0.3-6ubuntu1.3","description":"Library to read/write archive files","is_source":true},{"name":"libarchive12","version":"3.0.3-6ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.0.3-6ubuntu1.3"}],"trusty":[{"name":"libarchive","version":"3.1.2-7ubuntu2.3","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"bsdtar","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive13","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"}],"wily":[{"name":"libarchive","version":"3.1.2-11ubuntu0.15.10.2","description":"Library to read/write archive files","is_source":true},{"name":"libarchive13","version":"3.1.2-11ubuntu0.15.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.15.10.2"}],"xenial":[{"name":"libarchive","version":"3.1.2-11ubuntu0.16.04.2","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"bsdtar","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive13","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-8916","CVE-2015-8917","CVE-2015-8919","CVE-2015-8920","CVE-2015-8921","CVE-2015-8922","CVE-2015-8923","CVE-2015-8924","CVE-2015-8925","CVE-2015-8926","CVE-2015-8928","CVE-2015-8930","CVE-2015-8931","CVE-2015-8932","CVE-2015-8933","CVE-2015-8934","CVE-2016-4300","CVE-2016-4302","CVE-2016-4809","CVE-2016-5844"]}]},{"id":"CVE-2015-8917","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:49:49.105321+00:00","description":"\nbsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial\nof service (NULL pointer dereference and crash) via an invalid character in\nthe name of a cab file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"same patch as CVE-2015-8916"}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3033-1","https://www.cve.org/CVERecord?id=CVE-2015-8917"],"bugs":["https://github.com/libarchive/libarchive/issues/505"],"patches":{"libarchive":["upstream: https://github.com/libarchive/libarchive/commit/b2e2abb"]},"tags":{},"packages":[{"name":"libarchive","source":"https://ubuntu.com/security/cve?package=libarchive","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libarchive","debian":"https://tracker.debian.org/pkg/libarchive","statuses":[{"release_codename":"precise","status":"released","description":"3.0.3-6ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.1.2-7ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.0-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"3.1.2-11ubuntu0.15.10.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.1.2-11ubuntu0.16.04.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3033-1"],"notices":[{"id":"USN-3033-1","title":"libarchive vulnerabilities","summary":"libarchive could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-07-14T17:55:04.967093","description":"Hanno Böck discovered that libarchive contained multiple security issues\nwhen processing certain malformed archive files. A remote attacker could\nuse this issue to cause libarchive to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2015-8916, CVE-2015-8917\nCVE-2015-8919, CVE-2015-8920, CVE-2015-8921, CVE-2015-8922, CVE-2015-8923,\nCVE-2015-8924, CVE-2015-8925, CVE-2015-8926, CVE-2015-8928, CVE-2015-8930,\nCVE-2015-8931, CVE-2015-8932, CVE-2015-8933, CVE-2015-8934, CVE-2016-5844)\n\nMarcin \"Icewall\" Noga discovered that libarchive contained multiple\nsecurity issues when processing certain malformed archive files. A remote\nattacker could use this issue to cause libarchive to crash, resulting in a\ndenial of service, or possibly execute arbitrary code. (CVE-2016-4300,\nCVE-2016-4302)\n\nIt was discovered that libarchive incorrectly handled memory allocation\nwith large cpio symlinks. A remote attacker could use this issue to\npossibly cause libarchive to crash, resulting in a denial of service.\n(CVE-2016-4809)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libarchive","version":"3.0.3-6ubuntu1.3","description":"Library to read/write archive files","is_source":true},{"name":"libarchive12","version":"3.0.3-6ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.0.3-6ubuntu1.3"}],"trusty":[{"name":"libarchive","version":"3.1.2-7ubuntu2.3","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"bsdtar","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive13","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"}],"wily":[{"name":"libarchive","version":"3.1.2-11ubuntu0.15.10.2","description":"Library to read/write archive files","is_source":true},{"name":"libarchive13","version":"3.1.2-11ubuntu0.15.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.15.10.2"}],"xenial":[{"name":"libarchive","version":"3.1.2-11ubuntu0.16.04.2","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"bsdtar","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive13","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-8916","CVE-2015-8917","CVE-2015-8919","CVE-2015-8920","CVE-2015-8921","CVE-2015-8922","CVE-2015-8923","CVE-2015-8924","CVE-2015-8925","CVE-2015-8926","CVE-2015-8928","CVE-2015-8930","CVE-2015-8931","CVE-2015-8932","CVE-2015-8933","CVE-2015-8934","CVE-2016-4300","CVE-2016-4302","CVE-2016-4809","CVE-2016-5844"]}]},{"id":"CVE-2015-8916","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:49:49.105321+00:00","description":"\nbsdtar in libarchive before 3.2.0 returns a success code without filling\nthe entry when the header is a \"split file in multivolume RAR,\" which\nallows remote attackers to cause a denial of service (NULL pointer\ndereference and crash) via a crafted rar file.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"Reproducer doesn't work on precise"}],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3033-1","https://www.cve.org/CVERecord?id=CVE-2015-8916"],"bugs":["https://github.com/libarchive/libarchive/issues/504"],"patches":{"libarchive":["upstream: https://github.com/libarchive/libarchive/commit/b2e2abb"]},"tags":{},"packages":[{"name":"libarchive","source":"https://ubuntu.com/security/cve?package=libarchive","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libarchive","debian":"https://tracker.debian.org/pkg/libarchive","statuses":[{"release_codename":"precise","status":"not-affected","description":"verified via reproducer","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.1.2-7ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.0-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"3.1.2-11ubuntu0.15.10.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.1.2-11ubuntu0.16.04.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3033-1"],"notices":[{"id":"USN-3033-1","title":"libarchive vulnerabilities","summary":"libarchive could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-07-14T17:55:04.967093","description":"Hanno Böck discovered that libarchive contained multiple security issues\nwhen processing certain malformed archive files. A remote attacker could\nuse this issue to cause libarchive to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2015-8916, CVE-2015-8917\nCVE-2015-8919, CVE-2015-8920, CVE-2015-8921, CVE-2015-8922, CVE-2015-8923,\nCVE-2015-8924, CVE-2015-8925, CVE-2015-8926, CVE-2015-8928, CVE-2015-8930,\nCVE-2015-8931, CVE-2015-8932, CVE-2015-8933, CVE-2015-8934, CVE-2016-5844)\n\nMarcin \"Icewall\" Noga discovered that libarchive contained multiple\nsecurity issues when processing certain malformed archive files. A remote\nattacker could use this issue to cause libarchive to crash, resulting in a\ndenial of service, or possibly execute arbitrary code. (CVE-2016-4300,\nCVE-2016-4302)\n\nIt was discovered that libarchive incorrectly handled memory allocation\nwith large cpio symlinks. A remote attacker could use this issue to\npossibly cause libarchive to crash, resulting in a denial of service.\n(CVE-2016-4809)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libarchive","version":"3.0.3-6ubuntu1.3","description":"Library to read/write archive files","is_source":true},{"name":"libarchive12","version":"3.0.3-6ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.0.3-6ubuntu1.3"}],"trusty":[{"name":"libarchive","version":"3.1.2-7ubuntu2.3","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"bsdtar","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive13","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"}],"wily":[{"name":"libarchive","version":"3.1.2-11ubuntu0.15.10.2","description":"Library to read/write archive files","is_source":true},{"name":"libarchive13","version":"3.1.2-11ubuntu0.15.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.15.10.2"}],"xenial":[{"name":"libarchive","version":"3.1.2-11ubuntu0.16.04.2","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"bsdtar","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive13","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-8916","CVE-2015-8917","CVE-2015-8919","CVE-2015-8920","CVE-2015-8921","CVE-2015-8922","CVE-2015-8923","CVE-2015-8924","CVE-2015-8925","CVE-2015-8926","CVE-2015-8928","CVE-2015-8930","CVE-2015-8931","CVE-2015-8932","CVE-2015-8933","CVE-2015-8934","CVE-2016-4300","CVE-2016-4302","CVE-2016-4809","CVE-2016-5844"]}]},{"id":"CVE-2015-8903","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:49:49.105321+00:00","description":"\nThe ReadVICARImage function in coders/vicar.c in ImageMagick 6.x before\n6.9.0-5 Beta allows remote attackers to cause a denial of service (infinite\nloop) via a crafted VICAR file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is 0058-Fix-a-DOS-in-viccar-file-handling.patch"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/02/20/4","http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=26933","https://ubuntu.com/security/notices/USN-3131-1","https://www.cve.org/CVERecord?id=CVE-2015-8903"],"bugs":[""],"patches":{"imagemagick":["upstream: http://web.archive.org/web/20150428140926/http://trac.imagemagick.org/changeset/17856"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"precise","status":"released","description":"8:6.6.9.7-5ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"8:6.7.7.10-6ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.8.9.9-6","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"8:6.8.9.9-7ubuntu5","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"8:6.8.9.9-7ubuntu8","component":null,"pocket":"security"}]}],"notices_ids":["USN-3131-1"],"notices":[{"id":"USN-3131-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-11-21T14:07:40.268837","description":"It was discovered that ImageMagick incorrectly handled certain malformed\nimage files. If a user or automated system using ImageMagick were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program.\n","is_hidden":false,"release_packages":{"precise":[{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.5","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.5"},{"name":"libmagick++4","version":"8:6.6.9.7-5ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.5"},{"name":"libmagickcore4","version":"8:6.6.9.7-5ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.5"},{"name":"libmagickcore4-extra","version":"8:6.6.9.7-5ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.5"}],"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"}],"yakkety":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu8.1","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"}]},"type":"USN","cves_ids":["CVE-2014-8354","CVE-2014-8355","CVE-2014-8562","CVE-2014-8716","CVE-2014-9805","CVE-2014-9806","CVE-2014-9807","CVE-2014-9808","CVE-2014-9809","CVE-2014-9810","CVE-2014-9811","CVE-2014-9812","CVE-2014-9813","CVE-2014-9814","CVE-2014-9815","CVE-2014-9816","CVE-2014-9817","CVE-2014-9818","CVE-2014-9819","CVE-2014-9820","CVE-2014-9821","CVE-2014-9822","CVE-2014-9823","CVE-2014-9826","CVE-2014-9828","CVE-2014-9829","CVE-2014-9830","CVE-2014-9831","CVE-2014-9833","CVE-2014-9834","CVE-2014-9835","CVE-2014-9836","CVE-2014-9837","CVE-2014-9838","CVE-2014-9839","CVE-2014-9840","CVE-2014-9841","CVE-2014-9843","CVE-2014-9844","CVE-2014-9845","CVE-2014-9846","CVE-2014-9847","CVE-2014-9848","CVE-2014-9849","CVE-2014-9850","CVE-2014-9851","CVE-2014-9853","CVE-2014-9854","CVE-2014-9907","CVE-2015-8894","CVE-2015-8895","CVE-2015-8896","CVE-2015-8897","CVE-2015-8898","CVE-2015-8900","CVE-2015-8901","CVE-2015-8902","CVE-2015-8903","CVE-2015-8957","CVE-2015-8958","CVE-2015-8959","CVE-2016-4562","CVE-2016-4563","CVE-2016-4564","CVE-2016-5010","CVE-2016-5687","CVE-2016-5688","CVE-2016-5689","CVE-2016-5690","CVE-2016-5691","CVE-2016-5841","CVE-2016-5842","CVE-2016-6491","CVE-2016-6823","CVE-2016-7101","CVE-2016-7513","CVE-2016-7514","CVE-2016-7515","CVE-2016-7516","CVE-2016-7517","CVE-2016-7518","CVE-2016-7519","CVE-2016-7520","CVE-2016-7521","CVE-2016-7522","CVE-2016-7523","CVE-2016-7524","CVE-2016-7525","CVE-2016-7526","CVE-2016-7527","CVE-2016-7528","CVE-2016-7529","CVE-2016-7530","CVE-2016-7531","CVE-2016-7532","CVE-2016-7533","CVE-2016-7534","CVE-2016-7535","CVE-2016-7536","CVE-2016-7537","CVE-2016-7538","CVE-2016-7539","CVE-2016-7540"]}]},{"id":"CVE-2015-8902","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:49:49.105321+00:00","description":"\nThe ReadBlobByte function in coders/pdb.c in ImageMagick 6.x before 6.9.0-5\nBeta allows remote attackers to cause a denial of service (infinite loop)\nvia a crafted PDB file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is 0060-Fix-a-DOS-in-PDB-file-handling.patch"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/02/20/4","http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=26932","https://ubuntu.com/security/notices/USN-3131-1","https://www.cve.org/CVERecord?id=CVE-2015-8902"],"bugs":[""],"patches":{"imagemagick":["upstream: http://web.archive.org/web/20150428145652/http://trac.imagemagick.org/changeset/17855"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"precise","status":"released","description":"8:6.6.9.7-5ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.8.9.9-6","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"8:6.8.9.9-7ubuntu5","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"8:6.8.9.9-7ubuntu8","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"8:6.7.7.10-6ubuntu3.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3131-1"],"notices":[{"id":"USN-3131-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-11-21T14:07:40.268837","description":"It was discovered that ImageMagick incorrectly handled certain malformed\nimage files. If a user or automated system using ImageMagick were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program.\n","is_hidden":false,"release_packages":{"precise":[{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.5","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.5"},{"name":"libmagick++4","version":"8:6.6.9.7-5ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.5"},{"name":"libmagickcore4","version":"8:6.6.9.7-5ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.5"},{"name":"libmagickcore4-extra","version":"8:6.6.9.7-5ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.5"}],"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"}],"yakkety":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu8.1","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"}]},"type":"USN","cves_ids":["CVE-2014-8354","CVE-2014-8355","CVE-2014-8562","CVE-2014-8716","CVE-2014-9805","CVE-2014-9806","CVE-2014-9807","CVE-2014-9808","CVE-2014-9809","CVE-2014-9810","CVE-2014-9811","CVE-2014-9812","CVE-2014-9813","CVE-2014-9814","CVE-2014-9815","CVE-2014-9816","CVE-2014-9817","CVE-2014-9818","CVE-2014-9819","CVE-2014-9820","CVE-2014-9821","CVE-2014-9822","CVE-2014-9823","CVE-2014-9826","CVE-2014-9828","CVE-2014-9829","CVE-2014-9830","CVE-2014-9831","CVE-2014-9833","CVE-2014-9834","CVE-2014-9835","CVE-2014-9836","CVE-2014-9837","CVE-2014-9838","CVE-2014-9839","CVE-2014-9840","CVE-2014-9841","CVE-2014-9843","CVE-2014-9844","CVE-2014-9845","CVE-2014-9846","CVE-2014-9847","CVE-2014-9848","CVE-2014-9849","CVE-2014-9850","CVE-2014-9851","CVE-2014-9853","CVE-2014-9854","CVE-2014-9907","CVE-2015-8894","CVE-2015-8895","CVE-2015-8896","CVE-2015-8897","CVE-2015-8898","CVE-2015-8900","CVE-2015-8901","CVE-2015-8902","CVE-2015-8903","CVE-2015-8957","CVE-2015-8958","CVE-2015-8959","CVE-2016-4562","CVE-2016-4563","CVE-2016-4564","CVE-2016-5010","CVE-2016-5687","CVE-2016-5688","CVE-2016-5689","CVE-2016-5690","CVE-2016-5691","CVE-2016-5841","CVE-2016-5842","CVE-2016-6491","CVE-2016-6823","CVE-2016-7101","CVE-2016-7513","CVE-2016-7514","CVE-2016-7515","CVE-2016-7516","CVE-2016-7517","CVE-2016-7518","CVE-2016-7519","CVE-2016-7520","CVE-2016-7521","CVE-2016-7522","CVE-2016-7523","CVE-2016-7524","CVE-2016-7525","CVE-2016-7526","CVE-2016-7527","CVE-2016-7528","CVE-2016-7529","CVE-2016-7530","CVE-2016-7531","CVE-2016-7532","CVE-2016-7533","CVE-2016-7534","CVE-2016-7535","CVE-2016-7536","CVE-2016-7537","CVE-2016-7538","CVE-2016-7539","CVE-2016-7540"]}]},{"id":"CVE-2015-8901","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:49:49.105321+00:00","description":"\nImageMagick 6.x before 6.9.0-5 Beta allows remote attackers to cause a\ndenial of service (infinite loop) via a crafted MIFF file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is 0057-Fix-a-miff-security-bug.patch"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/02/20/4","http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=26931","https://ubuntu.com/security/notices/USN-3131-1","https://www.cve.org/CVERecord?id=CVE-2015-8901"],"bugs":[""],"patches":{"imagemagick":["upstream: http://trac.imagemagick.org/changeset/17854"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"precise","status":"released","description":"8:6.6.9.7-5ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"8:6.7.7.10-6ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.8.9.9-6","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"8:6.8.9.9-7ubuntu5","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"8:6.8.9.9-7ubuntu8","component":null,"pocket":"security"}]}],"notices_ids":["USN-3131-1"],"notices":[{"id":"USN-3131-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-11-21T14:07:40.268837","description":"It was discovered that ImageMagick incorrectly handled certain malformed\nimage files. If a user or automated system using ImageMagick were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program.\n","is_hidden":false,"release_packages":{"precise":[{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.5","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.5"},{"name":"libmagick++4","version":"8:6.6.9.7-5ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.5"},{"name":"libmagickcore4","version":"8:6.6.9.7-5ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.5"},{"name":"libmagickcore4-extra","version":"8:6.6.9.7-5ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.5"}],"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"}],"yakkety":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu8.1","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"}]},"type":"USN","cves_ids":["CVE-2014-8354","CVE-2014-8355","CVE-2014-8562","CVE-2014-8716","CVE-2014-9805","CVE-2014-9806","CVE-2014-9807","CVE-2014-9808","CVE-2014-9809","CVE-2014-9810","CVE-2014-9811","CVE-2014-9812","CVE-2014-9813","CVE-2014-9814","CVE-2014-9815","CVE-2014-9816","CVE-2014-9817","CVE-2014-9818","CVE-2014-9819","CVE-2014-9820","CVE-2014-9821","CVE-2014-9822","CVE-2014-9823","CVE-2014-9826","CVE-2014-9828","CVE-2014-9829","CVE-2014-9830","CVE-2014-9831","CVE-2014-9833","CVE-2014-9834","CVE-2014-9835","CVE-2014-9836","CVE-2014-9837","CVE-2014-9838","CVE-2014-9839","CVE-2014-9840","CVE-2014-9841","CVE-2014-9843","CVE-2014-9844","CVE-2014-9845","CVE-2014-9846","CVE-2014-9847","CVE-2014-9848","CVE-2014-9849","CVE-2014-9850","CVE-2014-9851","CVE-2014-9853","CVE-2014-9854","CVE-2014-9907","CVE-2015-8894","CVE-2015-8895","CVE-2015-8896","CVE-2015-8897","CVE-2015-8898","CVE-2015-8900","CVE-2015-8901","CVE-2015-8902","CVE-2015-8903","CVE-2015-8957","CVE-2015-8958","CVE-2015-8959","CVE-2016-4562","CVE-2016-4563","CVE-2016-4564","CVE-2016-5010","CVE-2016-5687","CVE-2016-5688","CVE-2016-5689","CVE-2016-5690","CVE-2016-5691","CVE-2016-5841","CVE-2016-5842","CVE-2016-6491","CVE-2016-6823","CVE-2016-7101","CVE-2016-7513","CVE-2016-7514","CVE-2016-7515","CVE-2016-7516","CVE-2016-7517","CVE-2016-7518","CVE-2016-7519","CVE-2016-7520","CVE-2016-7521","CVE-2016-7522","CVE-2016-7523","CVE-2016-7524","CVE-2016-7525","CVE-2016-7526","CVE-2016-7527","CVE-2016-7528","CVE-2016-7529","CVE-2016-7530","CVE-2016-7531","CVE-2016-7532","CVE-2016-7533","CVE-2016-7534","CVE-2016-7535","CVE-2016-7536","CVE-2016-7537","CVE-2016-7538","CVE-2016-7539","CVE-2016-7540"]}]},{"id":"CVE-2015-8900","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:49:49.105321+00:00","description":"\nThe ReadHDRImage function in coders/hdr.c in ImageMagick 6.x and 7.x allows\nremote attackers to cause a denial of service (infinite loop) via a crafted\nHDR file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is 0059-Fix-a-DOS-in-HDR-file.patch"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/02/20/4","http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=26929","https://ubuntu.com/security/notices/USN-3131-1","https://www.cve.org/CVERecord?id=CVE-2015-8900"],"bugs":[""],"patches":{"imagemagick":["upstream: http://web.archive.org/web/20150501030131/http://trac.imagemagick.org/changeset/17845","upstream: http://web.archive.org/web/20150429001241/http://trac.imagemagick.org/changeset/17846"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"precise","status":"released","description":"8:6.6.9.7-5ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.8.9.9-6","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"8:6.8.9.9-7ubuntu5","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"8:6.8.9.9-7ubuntu8","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"8:6.7.7.10-6ubuntu3.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3131-1"],"notices":[{"id":"USN-3131-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-11-21T14:07:40.268837","description":"It was discovered that ImageMagick incorrectly handled certain malformed\nimage files. If a user or automated system using ImageMagick were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program.\n","is_hidden":false,"release_packages":{"precise":[{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.5","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.5"},{"name":"libmagick++4","version":"8:6.6.9.7-5ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.5"},{"name":"libmagickcore4","version":"8:6.6.9.7-5ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.5"},{"name":"libmagickcore4-extra","version":"8:6.6.9.7-5ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.5"}],"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"}],"yakkety":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu8.1","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"}]},"type":"USN","cves_ids":["CVE-2014-8354","CVE-2014-8355","CVE-2014-8562","CVE-2014-8716","CVE-2014-9805","CVE-2014-9806","CVE-2014-9807","CVE-2014-9808","CVE-2014-9809","CVE-2014-9810","CVE-2014-9811","CVE-2014-9812","CVE-2014-9813","CVE-2014-9814","CVE-2014-9815","CVE-2014-9816","CVE-2014-9817","CVE-2014-9818","CVE-2014-9819","CVE-2014-9820","CVE-2014-9821","CVE-2014-9822","CVE-2014-9823","CVE-2014-9826","CVE-2014-9828","CVE-2014-9829","CVE-2014-9830","CVE-2014-9831","CVE-2014-9833","CVE-2014-9834","CVE-2014-9835","CVE-2014-9836","CVE-2014-9837","CVE-2014-9838","CVE-2014-9839","CVE-2014-9840","CVE-2014-9841","CVE-2014-9843","CVE-2014-9844","CVE-2014-9845","CVE-2014-9846","CVE-2014-9847","CVE-2014-9848","CVE-2014-9849","CVE-2014-9850","CVE-2014-9851","CVE-2014-9853","CVE-2014-9854","CVE-2014-9907","CVE-2015-8894","CVE-2015-8895","CVE-2015-8896","CVE-2015-8897","CVE-2015-8898","CVE-2015-8900","CVE-2015-8901","CVE-2015-8902","CVE-2015-8903","CVE-2015-8957","CVE-2015-8958","CVE-2015-8959","CVE-2016-4562","CVE-2016-4563","CVE-2016-4564","CVE-2016-5010","CVE-2016-5687","CVE-2016-5688","CVE-2016-5689","CVE-2016-5690","CVE-2016-5691","CVE-2016-5841","CVE-2016-5842","CVE-2016-6491","CVE-2016-6823","CVE-2016-7101","CVE-2016-7513","CVE-2016-7514","CVE-2016-7515","CVE-2016-7516","CVE-2016-7517","CVE-2016-7518","CVE-2016-7519","CVE-2016-7520","CVE-2016-7521","CVE-2016-7522","CVE-2016-7523","CVE-2016-7524","CVE-2016-7525","CVE-2016-7526","CVE-2016-7527","CVE-2016-7528","CVE-2016-7529","CVE-2016-7530","CVE-2016-7531","CVE-2016-7532","CVE-2016-7533","CVE-2016-7534","CVE-2016-7535","CVE-2016-7536","CVE-2016-7537","CVE-2016-7538","CVE-2016-7539","CVE-2016-7540"]}]},{"id":"CVE-2015-8899","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:49:49.105321+00:00","description":"\nDnsmasq before 2.76 allows remote servers to cause a denial of service\n(crash) via a reply with an empty DNS address that has an (1) A or (2) AAAA\nrecord defined locally.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"introduced in 2.73"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2016q2/010479.html","https://ubuntu.com/security/notices/USN-3009-1","https://www.cve.org/CVERecord?id=CVE-2015-8899"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/dnsmasq/+bug/1581181"],"patches":{"dnsmasq":["upstream: http://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=41a8d9e99be9f2cc8b02051dd322cb45e0faac87"]},"tags":{},"packages":[{"name":"dnsmasq","source":"https://ubuntu.com/security/cve?package=dnsmasq","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dnsmasq","debian":"https://tracker.debian.org/pkg/dnsmasq","statuses":[{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.76-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"2.75-1ubuntu0.15.10.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.75-1ubuntu0.16.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3009-1"],"notices":[{"id":"USN-3009-1","title":"Dnsmasq vulnerability","summary":"Dnsmasq could be made to crash if it received specially crafted network\ntraffic.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2016-06-20T16:35:09.888728","description":"Edwin Török discovered that Dnsmasq incorrectly handled certain CNAME\nresponses. A remote attacker could use this issue to cause Dnsmasq to\ncrash, resulting in a denial of service.\n","is_hidden":false,"release_packages":{"wily":[{"name":"dnsmasq","version":"2.75-1ubuntu0.15.10.1","description":"Small caching DNS proxy and DHCP/TFTP server","is_source":true},{"name":"dnsmasq","version":"2.75-1ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dnsmasq","version_link":"https://launchpad.net/ubuntu/+source/dnsmasq/2.75-1ubuntu0.15.10.1"},{"name":"dnsmasq-base","version":"2.75-1ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dnsmasq","version_link":"https://launchpad.net/ubuntu/+source/dnsmasq/2.75-1ubuntu0.15.10.1"},{"name":"dnsmasq-utils","version":"2.75-1ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dnsmasq","version_link":"https://launchpad.net/ubuntu/+source/dnsmasq/2.75-1ubuntu0.15.10.1"}],"xenial":[{"name":"dnsmasq","version":"2.75-1ubuntu0.16.04.1","description":"Small caching DNS proxy and DHCP/TFTP server","is_source":true},{"name":"dnsmasq","version":"2.75-1ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dnsmasq","version_link":"https://launchpad.net/ubuntu/+source/dnsmasq/2.75-1ubuntu0.16.04.1","pocket":"security"},{"name":"dnsmasq-base","version":"2.75-1ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dnsmasq","version_link":"https://launchpad.net/ubuntu/+source/dnsmasq/2.75-1ubuntu0.16.04.1","pocket":"security"},{"name":"dnsmasq-utils","version":"2.75-1ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dnsmasq","version_link":"https://launchpad.net/ubuntu/+source/dnsmasq/2.75-1ubuntu0.16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-8899"]}]}],"offset":61880,"limit":20,"total_results":79316}