Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-57970

Опубликовано: 16 фев. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 4

Описание

libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.

РелизСтатусПримечание
devel

released

3.7.7-0ubuntu2
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

not-affected

code not present
focal

not-affected

code not present
jammy

not-affected

code not present
noble

not-affected

code not present
oracular

not-affected

code not present
upstream

not-affected

debian: Vulnerable code introduced later

Показывать по

EPSS

Процентиль: 1%
0.00012
Низкий

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4
redhat
6 месяцев назад

libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.

CVSS3: 4
nvd
6 месяцев назад

libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.

CVSS3: 4
debian
6 месяцев назад

libarchive through 3.7.7 has a heap-based buffer over-read in header_g ...

CVSS3: 4
github
6 месяцев назад

libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.

oracle-oval
около 1 месяца назад

ELSA-2025-7510: libarchive security update (MODERATE)

EPSS

Процентиль: 1%
0.00012
Низкий

4 Medium

CVSS3