CVE-2007-3645
published 2007-07-15CVE-2007-3645: archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (crash) via (1) an end-of-file…
PriorityP414medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
3.44%
87.6th percentile
archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (crash) via (1) an end-of-file condition within a tar header that follows a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive, which results in a NULL pointer dereference, a different issue than CVE-2007-3644.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libarchive | < libarchive 2.2.4-1 (bookworm) | libarchive 2.2.4-1 (bookworm) |
| freebsd | libarchive | <= 2.2.3 | — |
| libarchive | libarchive | >= 0 < 2.2.4-1 | 2.2.4-1 |
| libarchive | libarchive | >= 0 < 2.2.4-1 | 2.2.4-1 |
| libarchive | libarchive | >= 0 < 2.2.4-1 | 2.2.4-1 |
| libarchive | libarchive | >= 0 < 2.2.4-1 | 2.2.4-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wc53-cvcx-2wqx: archive_read_support_format_tar
ghsa_unreviewed·2022-05-01·CVSS 4.3
CVE-2007-3645 [MEDIUM] GHSA-wc53-cvcx-2wqx: archive_read_support_format_tar
archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (crash) via (1) an end-of-file condition within a tar header that follows a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive, which results in a NULL pointer dereference, a different issue than CVE-2007-3644.
OSV
CVE-2007-3645: archive_read_support_format_tar
osv·2007-07-15·CVSS 4.3
CVE-2007-3645 [MEDIUM] CVE-2007-3645: archive_read_support_format_tar
archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (crash) via (1) an end-of-file condition within a tar header that follows a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive, which results in a NULL pointer dereference, a different issue than CVE-2007-3644.
BSD
FreeBSD-SA-07:05.libarchive: Errors handling corrupt tar files in libarchive(3)
bsd_advisories·2007-07-12·CVSS 9.3
CVE-2007-3641 [CRITICAL] FreeBSD-SA-07:05.libarchive: Errors handling corrupt tar files in libarchive(3)
FreeBSD-SA-07:05.libarchive Security Advisory
The FreeBSD Project
Topic: Errors handling corrupt tar files in libarchive(3)
Category: core
Module: libarchive
Announced: 2007-07-12
Credits: CPNI, CERT-FI, Tim Kientzle, Colin Percival
Affects: FreeBSD 5.3 and later.
Corrected: 2007-07-12 15:00:44 UTC (RELENG_6, 6.2-STABLE)
2007-07-12 15:01:14 UTC (RELENG_6_2, 6.2-RELEASE-p6)
2007-07-12 15:01:32 UTC (RELENG_6_1, 6.1-RELEASE-p18)
2007-07-12 15:01:42 UTC (RELENG_5, 5.5-STABLE)
2007-07-12 15:01:56 UTC (RELENG_5_5, 5.5-RELEASE-p14)
CVE Name: CVE-2007-3641, CVE-2007-3644, CVE-2007-3645
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
The libarchive library prov
Debian
CVE-2007-3645: libarchive - archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assiste...
vendor_debian·2007·CVSS 4.3
CVE-2007-3645 [MEDIUM] CVE-2007-3645: libarchive - archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assiste...
archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (crash) via (1) an end-of-file condition within a tar header that follows a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive, which results in a NULL pointer dereference, a different issue than CVE-2007-3644.
Scope: local
bookworm: resolved (fixed in 2.2.4-1)
bullseye: resolved (fixed in 2.2.4-1)
forky: resolved (fixed in 2.2.4-1)
sid: resolved (fixed in 2.2.4-1)
trixie: resolved (fixed in 2.2.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-5707 openldap slapd DoS via objectClasses attribute
bugzilla·2007-10-31·CVSS 7.1
CVE-2007-5707 [HIGH] CVE-2007-5707 openldap slapd DoS via objectClasses attribute
CVE-2007-5707 openldap slapd DoS via objectClasses attribute
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-5707 to the following vulnerability:
OpenLDAP before 2.3.39 allows remote attackers to cause a denial of
service (slapd crash) via an LDAP request with a malformed
objectClasses attribute. NOTE: this has been reported as a
double-free, but the reports are inconsistent.
References:
http://www.openldap.org/its/index.cgi/Software%20Bugs?id=5119
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=440632
http://www.openldap.org/lists/openldap-announce/200710/msg00001.html
http://www.securityfocus.com/bid/26245
http://www.frsirt.com/english/advisories/2007/3645
http://secunia.com/advisories/27424
Discussion:
Upstream patch:
http://www.openldap.org/devel/cvsweb.cgi/
Bugzilla
CVE-2007-5708 openldap slapd pcache overlay DoS via non-null teminated string
bugzilla·2007-10-31·CVSS 7.1
CVE-2007-5708 [HIGH] CVE-2007-5708 openldap slapd pcache overlay DoS via non-null teminated string
CVE-2007-5708 openldap slapd pcache overlay DoS via non-null teminated string
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-5708 to the following vulnerability:
slapo-pcache (overlays/pcache.c) in slapd in OpenLDAP before 2.3.39,
when running as a proxy-caching server, allocates memory using a
malloc variant instead of calloc, which prevents an array from being
initiialized properly and might allow attackers to cause a denial of
service (segmentation fault) via unknown vectors that prevent the
array from being null terminated.
References:
http://www.openldap.org/its/index.cgi/Software%20Bugs?id=5163
http://www.openldap.org/lists/openldap-announce/200710/msg00001.html
http://www.securityfocus.com/bid/26245
http://www.frsirt.com/english/advisories/2007/3645
http://s
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=432924http://osvdb.org/38093http://osvdb.org/38094http://people.freebsd.org/~kientzle/libarchive/http://secunia.com/advisories/26050http://secunia.com/advisories/26062http://secunia.com/advisories/26355http://secunia.com/advisories/28377http://security.freebsd.org/advisories/FreeBSD-SA-07:05.libarchive.aschttp://security.freebsd.org/patches/SA-07:05/libarchive.patchhttp://security.gentoo.org/glsa/glsa-200708-03.xmlhttp://www.debian.org/security/2008/dsa-1455http://www.novell.com/linux/security/advisories/2007_15_sr.htmlhttp://www.securityfocus.com/bid/24885http://www.securitytracker.com/id?1018379http://www.vupen.com/english/advisories/2007/2521https://exchange.xforce.ibmcloud.com/vulnerabilities/35404http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=432924http://osvdb.org/38093http://osvdb.org/38094http://people.freebsd.org/~kientzle/libarchive/http://secunia.com/advisories/26050http://secunia.com/advisories/26062http://secunia.com/advisories/26355http://secunia.com/advisories/28377http://security.freebsd.org/advisories/FreeBSD-SA-07:05.libarchive.aschttp://security.freebsd.org/patches/SA-07:05/libarchive.patchhttp://security.gentoo.org/glsa/glsa-200708-03.xmlhttp://www.debian.org/security/2008/dsa-1455http://www.novell.com/linux/security/advisories/2007_15_sr.htmlhttp://www.securityfocus.com/bid/24885http://www.securitytracker.com/id?1018379http://www.vupen.com/english/advisories/2007/2521https://exchange.xforce.ibmcloud.com/vulnerabilities/35404
2007-07-15
Published