Search CVE reports


Toggle filters

11 – 20 of 94 results


CVE-2025-25724

Medium priority

Some fixes available 6 of 9

list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of...

1 affected package

libarchive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2025-1632

Low priority
Fixed

A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the...

1 affected package

libarchive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Fixed Not affected Not affected Not affected
Show less packages

CVE-2024-57970

Medium priority
Not affected

libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.

1 affected package

libarchive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-48958

Medium priority
Fixed

execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.

1 affected package

libarchive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Fixed Fixed Not affected Not affected
Show less packages

CVE-2024-48957

Medium priority
Fixed

execute_filter_audio in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.

1 affected package

libarchive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Fixed Fixed Not affected Not affected
Show less packages

CVE-2024-37407

Medium priority
Not affected

Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled. This occurs in slurp_central_directory in archive_read_support_format_zip.c.

1 affected package

libarchive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-26256

Medium priority
Fixed

Libarchive Remote Code Execution Vulnerability

1 affected package

libarchive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Fixed Fixed Not affected Not affected
Show less packages

CVE-2024-20696

Medium priority

Some fixes available 6 of 9

Windows libarchive Remote Code Execution Vulnerability

1 affected package

libarchive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2023-30571

Negligible priority
Ignored

Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with...

1 affected package

libarchive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Ignored Ignored Ignored
Show less packages

CVE-2022-36227

Low priority

Some fixes available 5 of 6

In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE:...

1 affected package

libarchive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Not affected Fixed Fixed Fixed
Show less packages