CVE-2024-48615
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-48615 is a newly identified vulnerability affecting libarchive versions 3.7.6 and older. This issue results in a Null Pointer Dereference (NPD) during the execution of the 'bsdtar' program, specifically in the function 'header_pax_extension' located at 'rchive_read_support_format_tar.c:1844:8'. Exploitation of this NPD vulnerability could potentially lead to arbitrary code execution or a denial-of-service attack, posing a significant threat to systems using the affected version of libarchive. Users are advised to update to the latest stable release as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Libarchive
Affected Vendors
- Libarchive