Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-48615

Опубликовано: 28 мар. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchive_read_support_format_tar.c:1844:8.

A flaw was found in Libarchive's bsdtar component. This vulnerability allows an attacker to trigger a NULL pointer dereference, leading to a crash and potential denial of service (DoS) via a crafted TAR archive.

Отчет

This vulnerability is rated as an Important severity because it allows an attacker to trigger a NULL pointer dereference in Libarchive's bsdtar component. By providing a specially crafted TAR archive, an attacker can cause a crash, resulting in a denial of service (DoS), making it a significant concern for affected systems.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libarchiveNot affected
Red Hat Enterprise Linux 6libarchiveAffected
Red Hat Enterprise Linux 7libarchiveNot affected
Red Hat Enterprise Linux 8libarchiveNot affected
Red Hat Enterprise Linux 9libarchiveNot affected
Red Hat OpenShift Container Platform 4rhcosWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2355784libarchive: Null Pointer Dereference in Libarchive

EPSS

Процентиль: 21%
0.00067
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchive_read_support_format_tar.c:1844:8.

CVSS3: 7.5
nvd
5 месяцев назад

Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchive_read_support_format_tar.c:1844:8.

CVSS3: 7.5
msrc
5 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
5 месяцев назад

Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier ...

CVSS3: 7.5
redos
20 дней назад

Уязвимость libarchive

EPSS

Процентиль: 21%
0.00067
Низкий

7.5 High

CVSS3