CVE-2007-3641
published 2007-07-14CVE-2007-3641: archive_read_support_format_tar.c in libarchive before 2.2.4 does not properly compute the length of a certain buffer when processing a malformed pax extension…
PriorityP342critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
7.43%
93.8th percentile
archive_read_support_format_tar.c in libarchive before 2.2.4 does not properly compute the length of a certain buffer when processing a malformed pax extension header, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PAX or (2) TAR archive that triggers a buffer overflow.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libarchive | < libarchive 2.2.4-1 (bookworm) | libarchive 2.2.4-1 (bookworm) |
| freebsd | libarchive | <= 2.2.3 | — |
| libarchive | libarchive | >= 0 < 2.2.4-1 | 2.2.4-1 |
| libarchive | libarchive | >= 0 < 2.2.4-1 | 2.2.4-1 |
| libarchive | libarchive | >= 0 < 2.2.4-1 | 2.2.4-1 |
| libarchive | libarchive | >= 0 < 2.2.4-1 | 2.2.4-1 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-72gg-m2hj-9c97: archive_read_support_format_tar
ghsa_unreviewed·2022-05-01
CVE-2007-3641 [HIGH] GHSA-72gg-m2hj-9c97: archive_read_support_format_tar
archive_read_support_format_tar.c in libarchive before 2.2.4 does not properly compute the length of a certain buffer when processing a malformed pax extension header, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PAX or (2) TAR archive that triggers a buffer overflow.
OSV
CVE-2007-3641: archive_read_support_format_tar
osv·2007-07-14·CVSS 9.3
CVE-2007-3641 [CRITICAL] CVE-2007-3641: archive_read_support_format_tar
archive_read_support_format_tar.c in libarchive before 2.2.4 does not properly compute the length of a certain buffer when processing a malformed pax extension header, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PAX or (2) TAR archive that triggers a buffer overflow.
BSD
FreeBSD-SA-07:05.libarchive: Errors handling corrupt tar files in libarchive(3)
bsd_advisories·2007-07-12·CVSS 9.3
CVE-2007-3641 [CRITICAL] FreeBSD-SA-07:05.libarchive: Errors handling corrupt tar files in libarchive(3)
FreeBSD-SA-07:05.libarchive Security Advisory
The FreeBSD Project
Topic: Errors handling corrupt tar files in libarchive(3)
Category: core
Module: libarchive
Announced: 2007-07-12
Credits: CPNI, CERT-FI, Tim Kientzle, Colin Percival
Affects: FreeBSD 5.3 and later.
Corrected: 2007-07-12 15:00:44 UTC (RELENG_6, 6.2-STABLE)
2007-07-12 15:01:14 UTC (RELENG_6_2, 6.2-RELEASE-p6)
2007-07-12 15:01:32 UTC (RELENG_6_1, 6.1-RELEASE-p18)
2007-07-12 15:01:42 UTC (RELENG_5, 5.5-STABLE)
2007-07-12 15:01:56 UTC (RELENG_5_5, 5.5-RELEASE-p14)
CVE Name: CVE-2007-3641, CVE-2007-3644, CVE-2007-3645
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
The libarchive library prov
Debian
CVE-2007-3641: libarchive - archive_read_support_format_tar.c in libarchive before 2.2.4 does not properly c...
vendor_debian·2007·CVSS 9.3
CVE-2007-3641 [CRITICAL] CVE-2007-3641: libarchive - archive_read_support_format_tar.c in libarchive before 2.2.4 does not properly c...
archive_read_support_format_tar.c in libarchive before 2.2.4 does not properly compute the length of a certain buffer when processing a malformed pax extension header, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PAX or (2) TAR archive that triggers a buffer overflow.
Scope: local
bookworm: resolved (fixed in 2.2.4-1)
bullseye: resolved (fixed in 2.2.4-1)
forky: resolved (fixed in 2.2.4-1)
sid: resolved (fixed in 2.2.4-1)
trixie: resolved (fixed in 2.2.4-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=432924http://osvdb.org/38092http://people.freebsd.org/~kientzle/libarchive/http://secunia.com/advisories/26050http://secunia.com/advisories/26062http://secunia.com/advisories/26355http://secunia.com/advisories/28377http://security.freebsd.org/advisories/FreeBSD-SA-07:05.libarchive.aschttp://security.freebsd.org/patches/SA-07:05/libarchive.patchhttp://security.gentoo.org/glsa/glsa-200708-03.xmlhttp://www.debian.org/security/2008/dsa-1455http://www.novell.com/linux/security/advisories/2007_15_sr.htmlhttp://www.securityfocus.com/bid/24885http://www.securitytracker.com/id?1018379http://www.vupen.com/english/advisories/2007/2521https://exchange.xforce.ibmcloud.com/vulnerabilities/35405http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=432924http://osvdb.org/38092http://people.freebsd.org/~kientzle/libarchive/http://secunia.com/advisories/26050http://secunia.com/advisories/26062http://secunia.com/advisories/26355http://secunia.com/advisories/28377http://security.freebsd.org/advisories/FreeBSD-SA-07:05.libarchive.aschttp://security.freebsd.org/patches/SA-07:05/libarchive.patchhttp://security.gentoo.org/glsa/glsa-200708-03.xmlhttp://www.debian.org/security/2008/dsa-1455http://www.novell.com/linux/security/advisories/2007_15_sr.htmlhttp://www.securityfocus.com/bid/24885http://www.securitytracker.com/id?1018379http://www.vupen.com/english/advisories/2007/2521https://exchange.xforce.ibmcloud.com/vulnerabilities/35405
2007-07-14
Published