Search CVE reports


Toggle filters

11 – 20 of 90 results


CVE-2024-48615

Medium priority
Not affected

Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchive_read_support_format_tar.c:1844:8.

1 affected package

libarchive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-37407

Medium priority
Not affected

Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled. This occurs in slurp_central_directory in archive_read_support_format_zip.c.

1 affected package

libarchive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-26256

Medium priority
Fixed

Libarchive Remote Code Execution Vulnerability

1 affected package

libarchive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Fixed Fixed Not affected Not affected
Show less packages

CVE-2024-20696

Medium priority

Some fixes available 5 of 8

Windows libarchive Remote Code Execution Vulnerability

1 affected package

libarchive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2023-30571

Negligible priority
Ignored

Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with...

1 affected package

libarchive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Ignored Ignored Ignored
Show less packages

CVE-2022-36227

Low priority

Some fixes available 5 of 6

In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE:...

1 affected package

libarchive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Not affected Fixed Fixed Fixed
Show less packages

CVE-2022-28066

Medium priority
Fixed

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-26280. Reason: This candidate is a duplicate of CVE-2022-26280. Notes: All CVE users should reference CVE-2022-26280 instead of this candidate. All references...

1 affected package

libarchive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Fixed Fixed Not affected
Show less packages

CVE-2022-26280

Medium priority
Fixed

Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init.

1 affected package

libarchive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Fixed Fixed Not affected
Show less packages

CVE-2021-36976

Medium priority

Some fixes available 3 of 5

libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).

1 affected package

libarchive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Fixed Fixed Not affected
Show less packages

CVE-2021-31566

Low priority

Some fixes available 2 of 6

An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim...

1 affected package

libarchive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libarchive Not affected Not affected Fixed Vulnerable
Show less packages