CVE-2024-57970

Name
CVE-2024-57970
Description
libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.
NVD Severity
low
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://github.com/libarchive/libarchive/issues/2415
cve@mitre.org https://github.com/libarchive/libarchive/pull/2422

Match rules

CPE URI Source package Min version Max version
libarchive >= 0 <= 3.7.7

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
libarchive edge-main 3.7.7-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable