Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-57970

Опубликовано: 16 фев. 2025
Источник: debian

Описание

libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libarchivenot-affectedpackage

Примечания

  • https://github.com/libarchive/libarchive/pull/2422

  • https://github.com/libarchive/libarchive/issues/2415

  • Introduced by: https://github.com/libarchive/libarchive/commit/2d8a5760c5ec553283a95a1aaca746f6eb472d0f (v3.7.5)

  • Fixed by: https://github.com/libarchive/libarchive/commit/82912103214506316bd9990d73f33d743d55f570 (master)

  • Fixed by: https://github.com/libarchive/libarchive/commit/e0362b7f1a51b6c59ea06257a8f41e6ae3c7000f (v3.7.8)

Связанные уязвимости

CVSS3: 4
ubuntu
6 месяцев назад

libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.

CVSS3: 4
redhat
6 месяцев назад

libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.

CVSS3: 4
nvd
6 месяцев назад

libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.

CVSS3: 4
github
6 месяцев назад

libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.

oracle-oval
около 1 месяца назад

ELSA-2025-7510: libarchive security update (MODERATE)