Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-48615

Опубликовано: 28 мар. 2025
Источник: redhat
CVSS3: 7.5

Описание

Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchive_read_support_format_tar.c:1844:8.

A flaw was found in Libarchive's bsdtar component. This vulnerability allows an attacker to trigger a NULL pointer dereference, leading to a crash and potential denial of service (DoS) via a crafted TAR archive.

Отчет

This vulnerability is rated as an Important severity because it allows an attacker to trigger a NULL pointer dereference in Libarchive's bsdtar component. By providing a specially crafted TAR archive, an attacker can cause a crash, resulting in a denial of service (DoS), making it a significant concern for affected systems.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libarchiveNot affected
Red Hat Enterprise Linux 6libarchiveAffected
Red Hat Enterprise Linux 7libarchiveNot affected
Red Hat Enterprise Linux 8libarchiveNot affected
Red Hat Enterprise Linux 9libarchiveNot affected
Red Hat OpenShift Container Platform 4rhcosWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2355784libarchive: Null Pointer Dereference in Libarchive

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
11 месяцев назад

Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchive_read_support_format_tar.c:1844:8.

CVSS3: 7.5
nvd
11 месяцев назад

Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchive_read_support_format_tar.c:1844:8.

CVSS3: 7.5
msrc
10 месяцев назад

Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchive_read_support_format_tar.c:1844:8.

CVSS3: 7.5
debian
11 месяцев назад

Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier ...

CVSS3: 7.5
github
11 месяцев назад

Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchive_read_support_format_tar.c:1844:8.

7.5 High

CVSS3

Уязвимость CVE-2024-48615