cbcvebase.

Debian Libarchive vulnerabilities

75 known vulnerabilities affecting debian/libarchive.

Total CVEs
75
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH28MEDIUM31LOW15

Vulnerabilities

Page 1 of 4
CVE-2016-1541P3HIGHCVSS 8.8fixed in libarchive 3.1.2-11.1 (bookworm)2016
CVE-2016-1541 [HIGH] CVE-2016-1541: libarchive - Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read... Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to execute arbitrary code via crafted entry-size values in a ZIP archive. Scope: local bookworm: resolved (fixed in 3.1.2-11.1) bullseye: resolved (fixed in 3.1.2-11.1) forky: resolved (fixed in 3.1.2-11.1) sid: re
debian
CVE-2022-36227P3CRITICALCVSS 9.8fixed in libarchive 3.6.2-1 (bookworm)2022
CVE-2022-36227 [CRITICAL] CVE-2022-36227: libarchive - In libarchive before 3.6.2, the software does not check for an error after calli... In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to
debian
CVE-2016-6250P3LOWCVSS 8.6fixed in libarchive 3.2.1-1 (bookworm)2016
CVE-2016-6250 [HIGH] CVE-2016-6250: libarchive - Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote ... Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors related to verifying filename lengths when writing an ISO9660 archive, which trigger a buffer overflow. Scope: local bookworm: resolved (fixed in 3.2.1-1) bullseye: resolved (fixed in 3.2.1-
debian
CVE-2016-5418P3HIGHCVSS 7.5fixed in libarchive 3.2.1-4 (bookworm)2016
CVE-2016-5418 [HIGH] CVE-2016-5418: libarchive - The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive ... The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive file. Scope: local bookworm: resolved (fixed in 3.2.1-4) bullseye: resolved (fixed in 3.2.1-4) forky: resolved (fixed in 3.2.1-4) sid: resolved (fixed in 3.2.1-4) trixie:
debian
CVE-2018-1000878P3HIGHCVSS 8.8fixed in libarchive 3.3.3-2 (bookworm)2018
CVE-2018-1000878 [HIGH] CVE-2018-1000878: libarchive - libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (rele... libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c that can result in Crash/DoS - it is unknown if RCE is possible. This attack appear to be exploitable via the victim must open a specially crafted RAR
debian
CVE-2018-1000877P3HIGHCVSS 8.8fixed in libarchive 3.3.3-2 (bookworm)2018
CVE-2018-1000877 [HIGH] CVE-2018-1000877: libarchive - libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (rele... libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c, parse_codes(), realloc(rar->lzss.window, new_size) with new_size = 0 that can result in Crash/DoS. This attack appear to be exploitable via the victim m
debian
CVE-2025-5914P3HIGHCVSS 7.8fixed in libarchive 3.6.2-1+deb12u3 (bookworm)2025
CVE-2025-5914 [HIGH] CVE-2025-5914: libarchive - A vulnerability has been identified in the libarchive library, specifically with... A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-se
debian
CVE-2007-3641P3LOWCVSS 9.3fixed in libarchive 2.2.4-1 (bookworm)2007
CVE-2007-3641 [CRITICAL] CVE-2007-3641: libarchive - archive_read_support_format_tar.c in libarchive before 2.2.4 does not properly c... archive_read_support_format_tar.c in libarchive before 2.2.4 does not properly compute the length of a certain buffer when processing a malformed pax extension header, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PAX or (2) TAR archive that triggers a buffer overflow. Scop
debian
CVE-2016-4300P3HIGHCVSS 7.8fixed in libarchive 3.2.1-1 (bookworm)2016
CVE-2016-4300 [HIGH] CVE-2016-4300: libarchive - Integer overflow in the read_SubStreamsInfo function in archive_read_support_for... Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a 7zip file with a large number of substreams, which triggers a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 3.2.1-1) bullseye: resolved (fixed in 3.2.1-1) forky: resolve
debian
CVE-2024-20696P3HIGHCVSS 7.3fixed in libarchive 3.6.2-1+deb12u2 (bookworm)2024
CVE-2024-20696 [HIGH] CVE-2024-20696: libarchive - Windows libarchive Remote Code Execution Vulnerability Windows libarchive Remote Code Execution Vulnerability Scope: local bookworm: resolved (fixed in 3.6.2-1+deb12u2) bullseye: resolved (fixed in 3.4.3-2+deb11u2) forky: resolved (fixed in 3.7.4-1.1) sid: resolved (fixed in 3.7.4-1.1) trixie: resolved (fixed in 3.7.4-1.1)
debian
CVE-2016-8687P3HIGHCVSS 7.5fixed in libarchive 3.2.1-5 (bookworm)2016
CVE-2016-8687 [HIGH] CVE-2016-8687: libarchive - Stack-based buffer overflow in the safe_fprintf function in tar/util.c in libarc... Stack-based buffer overflow in the safe_fprintf function in tar/util.c in libarchive 3.2.1 allows remote attackers to cause a denial of service via a crafted non-printable multibyte character in a filename. Scope: local bookworm: resolved (fixed in 3.2.1-5) bullseye: resolved (fixed in 3.2.1-5) forky: resolved (fixed in 3.2.1-5) sid: resolved (fixed in 3.2.1-5) tri
debian
CVE-2015-8921P3HIGHCVSS 7.5fixed in libarchive 3.2.0-2 (bookworm)2015
CVE-2015-8921 [HIGH] CVE-2015-8921: libarchive - The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows... The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file. Scope: local bookworm: resolved (fixed in 3.2.0-2) bullseye: resolved (fixed in 3.2.0-2) forky: resolved (fixed in 3.2.0-2) sid: resolved (fixed in 3.2.0-2) trixie: resolved (fixed in 3.2.0-2)
debian
CVE-2015-2304P3MEDIUMCVSS 6.4fixed in libarchive 3.1.2-11 (bookworm)2015
CVE-2015-2304 [MEDIUM] CVE-2015-2304: libarchive - Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier... Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive. Scope: local bookworm: resolved (fixed in 3.1.2-11) bullseye: resolved (fixed in 3.1.2-11) forky: resolved (fixed in 3.1.2-11) sid: resolved (fixed in 3.1.2-11) trixie: resolved (fixed in 3.1.2-11)
debian
CVE-2016-4302P3HIGHCVSS 7.8fixed in libarchive 3.2.1-1 (bookworm)2016
CVE-2016-4302 [HIGH] CVE-2016-4302: libarchive - Heap-based buffer overflow in the parse_codes function in archive_read_support_f... Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a RAR file with a zero-sized dictionary. Scope: local bookworm: resolved (fixed in 3.2.1-1) bullseye: resolved (fixed in 3.2.1-1) forky: resolved (fixed in 3.2.1-1) sid: resolved (fixed in 3.2.1
debian
CVE-2020-9308P3HIGHCVSS 8.8fixed in libarchive 3.4.0-2 (bookworm)2020
CVE-2020-9308 [HIGH] CVE-2020-9308: libarchive - archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack... archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact. Scope: local bookworm: resolved (fixed in 3.4.0-2) bullseye: resolved (fixed in 3.4.0-2) forky: resolved (fixed in 3.4.0-2) sid: resolved (fixed i
debian
CVE-2019-18408P3HIGHCVSS 7.5fixed in libarchive 3.4.0-1 (bookworm)2019
CVE-2019-18408 [HIGH] CVE-2019-18408: libarchive - archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarc... archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol. Scope: local bookworm: resolved (fixed in 3.4.0-1) bullseye: resolved (fixed in 3.4.0-1) forky: resolved (fixed in 3.4.0-1) sid: resolved (fixed in 3.4.0-1) trixie: resolved (f
debian
CVE-2024-48958P3HIGHCVSS 7.8fixed in libarchive 3.6.2-1+deb12u1 (bookworm)2024
CVE-2024-48958 [HIGH] CVE-2024-48958: libarchive - execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3... execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst. Scope: local bookworm: resolved (fixed in 3.6.2-1+deb12u1) bullseye: resolved forky: resolved (fixed in 3.7.2-2.1) sid: resolved (fixed in 3.7.2-2.1) trixie: resolved (fixed in 3.7.2-2.1)
debian
CVE-2024-48957P3HIGHCVSS 7.8fixed in libarchive 3.6.2-1+deb12u1 (bookworm)2024
CVE-2024-48957 [HIGH] CVE-2024-48957: libarchive - execute_filter_audio in archive_read_support_format_rar.c in libarchive before 3... execute_filter_audio in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst. Scope: local bookworm: resolved (fixed in 3.6.2-1+deb12u1) bullseye: resolved forky: resolved (fixed in 3.7.2-2.1) sid: resolved (fixed in 3.7.2-2.1) trixie: resolved (fixed in 3.7.2-2.1)
debian
CVE-2021-31566P3HIGHCVSS 7.8fixed in libarchive 3.5.2-1 (bookworm)2021
CVE-2021-31566 [HIGH] CVE-2021-31566: libarchive - An improper link resolution flaw can occur while extracting an archive leading t... An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to gain more privileges in a syst
debian
CVE-2015-8919P3HIGHCVSS 7.5fixed in libarchive 3.2.0-2 (bookworm)2015
CVE-2015-8919 [HIGH] CVE-2015-8919: libarchive - The lha_read_file_extended_header function in archive_read_support_format_lha.c ... The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap) via a crafted (1) lzh or (2) lha file. Scope: local bookworm: resolved (fixed in 3.2.0-2) bullseye: resolved (fixed in 3.2.0-2) forky: resolved (fixed in 3.2.0-2) sid: resolved (fixed in
debian
Debian Libarchive vulnerabilities | cvebase