Use-after-free in Debian Linux - CVE-2015-8871

 

Use-after-free in Debian Linux - CVE-2015-8871

Published: September 21, 2016 / Updated: August 9, 2020


Vulnerability identifier: #VU40093
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-8871
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when processing unknown vectors. A remote attackers can have unspecified impact.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

Debian Linux
Gentoo Linux
Fedora
Opensuse
SUSE Package Hub for SUSE Linux Enterprise
media-libs/openjpeg
openjpeg2
mingw-openjpeg2

How to mitigate CVE-2015-8871

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

media-libs/openjpeg - update to 1.5.2
openjpeg2 - addressed in versions 2.1.1-1.fc23, 2.1.1-1.fc24
mingw-openjpeg2 - addressed in versions 2.1.1-1.fc23, 2.1.1-1.fc24

External References

Related Security Bulletins