Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-25724

Опубликовано: 02 мар. 2025
Источник: nvd
CVSS3: 4
CVSS3: 7.8
EPSS Низкий

Описание

list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:*
Версия до 3.7.7 (включая)

EPSS

Процентиль: 2%
0.00016
Низкий

4 Medium

CVSS3

7.8 High

CVSS3

Дефекты

CWE-252

Связанные уязвимости

CVSS3: 4
ubuntu
5 месяцев назад

list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.

CVSS3: 4
redhat
5 месяцев назад

list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.

CVSS3: 4
msrc
5 месяцев назад

Описание отсутствует

CVSS3: 4
debian
5 месяцев назад

list_item_verbose in tar/util.c in libarchive through 3.7.7 does not c ...

CVSS3: 4
github
5 месяцев назад

list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.

EPSS

Процентиль: 2%
0.00016
Низкий

4 Medium

CVSS3

7.8 High

CVSS3

Дефекты

CWE-252