Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2q66-6w43-8rm9

Опубликовано: 16 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4

Описание

libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.

libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.

EPSS

Процентиль: 16%
0.00243
Низкий

4 Medium

CVSS3

Дефекты

CWE-126

Связанные уязвимости

CVSS3: 4
ubuntu
больше 1 года назад

libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.

CVSS3: 4
redhat
больше 1 года назад

libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.

CVSS3: 4
nvd
больше 1 года назад

libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.

msrc
11 месяцев назад

libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.

CVSS3: 4
debian
больше 1 года назад

libarchive through 3.7.7 has a heap-based buffer over-read in header_g ...

EPSS

Процентиль: 16%
0.00243
Низкий

4 Medium

CVSS3

Дефекты

CWE-126