Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-25724

Опубликовано: 02 мар. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 4

Описание

list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.

РелизСтатусПримечание
devel

released

3.7.7-0ubuntu2.1
esm-infra-legacy/trusty

released

3.1.2-7ubuntu2.8+esm4
esm-infra-legacy/xenial

released

3.1.2-11ubuntu0.16.04.8+esm2
esm-infra/bionic

released

3.2.2-3.1ubuntu0.7+esm2
esm-infra/focal

released

3.4.0-2ubuntu1.5
esm-infra/xenial

released

3.1.2-11ubuntu0.16.04.8+esm2
focal

released

3.4.0-2ubuntu1.5
jammy

released

3.6.0-1ubuntu1.4
noble

released

3.7.2-2ubuntu0.4
oracular

released

3.7.4-1ubuntu0.2

Показывать по

EPSS

Процентиль: 28%
0.00351
Низкий

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4
redhat
больше 1 года назад

list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.

CVSS3: 4
nvd
больше 1 года назад

list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.

CVSS3: 4
msrc
больше 1 года назад

list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.

CVSS3: 4
debian
больше 1 года назад

list_item_verbose in tar/util.c in libarchive through 3.7.7 does not c ...

rocky
10 месяцев назад

Moderate: libarchive security update

EPSS

Процентиль: 28%
0.00351
Низкий

4 Medium

CVSS3