CVE-2024-57970

CVSS 3.1 Score 4 of 10 (medium)

Details

Published Feb 16, 2025
Updated: Feb 18, 2025
CWE ID 126

Summary

CVE-2024-57970 is a newly disclosed vulnerability affecting libarchive up to version 3.7.7. This issue involves a heap-based buffer over-read in the function "header_gnu_longlink" within "archive_read_support_format_tar.c". The vulnerability arises due to the library's mishandling of truncation in GNU long linknames found in TAR archives. Successful exploitation could result in arbitrary code execution or denial of service. Users are advised to update their libarchive installation as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share