libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 14 May 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| CPEs | cpe:/o:redhat:enterprise_linux:10.0 | |
| Vendors & Products |
Redhat
Redhat enterprise Linux |
Tue, 18 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Feb 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | libarchive: heap buffer over-read in header_gnu_longlink | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Sun, 16 Feb 2025 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname. | |
| Weaknesses | CWE-126 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-02-16T00:00:00.000Z
Updated: 2025-02-18T17:05:13.914Z
Reserved: 2025-02-16T00:00:00.000Z
Link: CVE-2024-57970
Updated: 2025-02-18T14:32:31.341Z
Status : Received
Published: 2025-02-16T04:15:21.843
Modified: 2025-02-18T17:15:19.130
Link: CVE-2024-57970