Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-57970

Опубликовано: 16 фев. 2025
Источник: redhat
CVSS3: 4
EPSS Низкий

Описание

libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.

A flaw was found in the libarchive library. A specially-crafted tar file may trigger a head-based buffer over-read condition due to incorrect handling of truncation in the middle of a long GNU linkname. This issue can cause an application crash leading to a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libarchiveOut of support scope
Red Hat Enterprise Linux 7libarchiveOut of support scope
Red Hat Enterprise Linux 8libarchiveOut of support scope
Red Hat Enterprise Linux 9libarchiveNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected
Red Hat Enterprise Linux 10libarchiveFixedRHSA-2025:751013.05.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-126
https://bugzilla.redhat.com/show_bug.cgi?id=2345954libarchive: heap buffer over-read in header_gnu_longlink

EPSS

Процентиль: 3%
0.00016
Низкий

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4
ubuntu
около 1 года назад

libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.

CVSS3: 4
nvd
около 1 года назад

libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.

msrc
7 месяцев назад

libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.

CVSS3: 4
debian
около 1 года назад

libarchive through 3.7.7 has a heap-based buffer over-read in header_g ...

rocky
6 месяцев назад

Moderate: libarchive security update

EPSS

Процентиль: 3%
0.00016
Низкий

4 Medium

CVSS3