Medium severity5.5NVD Advisory· Published Oct 24, 2017· Updated May 13, 2026
CVE-2017-15873
CVE-2017-15873
Description
The get_next_block function in archival/libarchive/decompress_bunzip2.c in BusyBox 1.27.2 has an Integer Overflow that may lead to a write access violation.
Affected products
7cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- git.busybox.net/busybox/commit/nvdIssue TrackingPatchThird Party Advisory
- bugs.busybox.net/show_bug.cginvdExploitIssue TrackingThird Party Advisory
- lists.debian.org/debian-lts-announce/2018/07/msg00037.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2021/02/msg00020.htmlnvdMailing ListThird Party Advisory
- usn.ubuntu.com/3935-1/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.