CVE-2024-57970
CVSS 3.1 Score 4 of 10 (medium)
Details
Published Feb 16, 2025
Updated: Feb 18, 2025
CWE ID 126
Summary
CVE-2024-57970 is a newly disclosed vulnerability affecting libarchive up to version 3.7.7. This issue involves a heap-based buffer over-read in the function "header_gnu_longlink" within "archive_read_support_format_tar.c". The vulnerability arises due to the library's mishandling of truncation in GNU long linknames found in TAR archives. Successful exploitation could result in arbitrary code execution or denial of service. Users are advised to update their libarchive installation as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Libarchive
Affected Vendors
- Libarchive