Debian Libarchive vulnerabilities
75 known vulnerabilities affecting debian/libarchive.
Total CVEs
75
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH28MEDIUM31LOW15
Vulnerabilities
Page 2 of 4
CVE-2016-4301P3HIGHCVSS 7.8fixed in libarchive 3.2.1-1 (bookworm)2016
CVE-2016-4301 [HIGH] CVE-2016-4301: libarchive - Stack-based buffer overflow in the parse_device function in archive_read_support...
Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a crafted mtree file.
Scope: local
bookworm: resolved (fixed in 3.2.1-1)
bullseye: resolved (fixed in 3.2.1-1)
forky: resolved (fixed in 3.2.1-1)
sid: resolved (fixed in 3.2.1-1)
trixie: res
debian
CVE-2017-5601P3HIGHCVSS 7.5fixed in libarchive 3.2.1-6 (bookworm)2017
CVE-2017-5601 [HIGH] CVE-2017-5601: libarchive - An error in the lha_read_file_header_1() function (archive_read_support_format_l...
An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-of-bounds read memory access and subsequently cause a crash via a specially crafted archive.
Scope: local
bookworm: resolved (fixed in 3.2.1-6)
bullseye: resolved (fixed in 3.2.1-6)
forky: resolved (fixed in 3.2.1-6)
si
debian
CVE-2021-23177P3HIGHCVSS 7.8fixed in libarchive 3.5.2-1 (bookworm)2021
CVE-2021-23177 [HIGH] CVE-2021-23177: libarchive - An improper link resolution flaw while extracting an archive can lead to changin...
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL of a file on the system and gain more privilege
debian
CVE-2015-8930P3HIGHCVSS 7.5fixed in libarchive 3.2.0-2 (bookworm)2015
CVE-2015-8930 [HIGH] CVE-2015-8930: libarchive - bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of s...
bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (infinite loop) via an ISO with a directory that is a member of itself.
Scope: local
bookworm: resolved (fixed in 3.2.0-2)
bullseye: resolved (fixed in 3.2.0-2)
forky: resolved (fixed in 3.2.0-2)
sid: resolved (fixed in 3.2.0-2)
trixie: resolved (fixed in 3.2.0-2)
debian
CVE-2017-14502P3HIGHCVSS 7.5fixed in libarchive 3.2.2-4.1 (bookworm)2017
CVE-2017-14502 [HIGH] CVE-2017-14502: libarchive - read_header in archive_read_support_format_rar.c in libarchive 3.3.2 suffers fro...
read_header in archive_read_support_format_rar.c in libarchive 3.3.2 suffers from an off-by-one error for UTF-16 names in RAR archives, leading to an out-of-bounds read in archive_read_format_rar_read_header.
Scope: local
bookworm: resolved (fixed in 3.2.2-4.1)
bullseye: resolved (fixed in 3.2.2-4.1)
forky: resolved (fixed in 3.2.2-4.1)
sid: resolved (fixed in 3.
debian
CVE-2015-8917P3HIGHCVSS 7.5fixed in libarchive 3.2.0-2 (bookworm)2015
CVE-2015-8917 [HIGH] CVE-2015-8917: libarchive - bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of s...
bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid character in the name of a cab file.
Scope: local
bookworm: resolved (fixed in 3.2.0-2)
bullseye: resolved (fixed in 3.2.0-2)
forky: resolved (fixed in 3.2.0-2)
sid: resolved (fixed in 3.2.0-2)
trixie: resolved (fixed in 3.2.0-2
debian
CVE-2015-8931P3HIGHCVSS 7.8fixed in libarchive 3.2.0-2 (bookworm)2015
CVE-2015-8931 [HIGH] CVE-2015-8931: libarchive - Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min func...
Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_read_support_format_mtree.c in libarchive before 3.2.0 allow remote attackers to have unspecified impact via a crafted mtree file, which triggers undefined behavior.
Scope: local
bookworm: resolved (fixed in 3.2.0-2)
bullseye: resolved (fixed in 3.2.0-2)
forky: resolved
debian
CVE-2025-25724P3LOWCVSS 4.0fixed in libarchive 3.8.4-1 (forky)2025
CVE-2025-25724 [MEDIUM] CVE-2025-25724: libarchive - list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an st...
list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.
Scope: local
bookworm: open
bullseye: open
forky: reso
debian
CVE-2016-8689P4HIGHCVSS 7.5fixed in libarchive 3.2.1-5 (bookworm)2016
CVE-2016-8689 [HIGH] CVE-2016-8689: libarchive - The read_Header function in archive_read_support_format_7zip.c in libarchive 3.2...
The read_Header function in archive_read_support_format_7zip.c in libarchive 3.2.1 allows remote attackers to cause a denial of service (out-of-bounds read) via multiple EmptyStream attributes in a header in a 7zip archive.
Scope: local
bookworm: resolved (fixed in 3.2.1-5)
bullseye: resolved (fixed in 3.2.1-5)
forky: resolved (fixed in 3.2.1-5)
sid: resolved (fixe
debian
CVE-2011-1777P4MEDIUMCVSS 6.8fixed in libarchive 2.8.5-5 (bookworm)2011
CVE-2011-1777 [MEDIUM] CVE-2011-1777: libarchive - Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functio...
Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functions in archive_read_support_format_iso9660.c in libarchive through 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ISO9660 image.
Scope: local
bookworm: resolved (fixed in 2.8.5-5)
bullseye: resolved (fixed
debian
CVE-2022-26280P4MEDIUMCVSS 6.5fixed in libarchive 3.6.2-1 (bookworm)2022
CVE-2022-26280 [MEDIUM] CVE-2022-26280: libarchive - Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the compon...
Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init.
Scope: local
bookworm: resolved (fixed in 3.6.2-1)
bullseye: resolved (fixed in 3.4.3-2+deb11u2)
forky: resolved (fixed in 3.6.2-1)
sid: resolved (fixed in 3.6.2-1)
trixie: resolved (fixed in 3.6.2-1)
debian
CVE-2016-4809P4HIGHCVSS 7.5fixed in libarchive 3.2.1-1 (bookworm)2016
CVE-2016-4809 [HIGH] CVE-2016-4809: libarchive - The archive_read_format_cpio_read_header function in archive_read_support_format...
The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a CPIO archive with a large symlink.
Scope: local
bookworm: resolved (fixed in 3.2.1-1)
bullseye: resolved (fixed in 3.2.1-1)
forky: resolved (fixed in 3.2.1-1)
sid: resolved
debian
CVE-2018-1000880P4MEDIUMCVSS 6.5fixed in libarchive 3.3.3-2 (bookworm)2018
CVE-2018-1000880 [MEDIUM] CVE-2018-1000880: libarchive - libarchive version commit 9693801580c0cf7c70e862d305270a16b52826a7 onwards (rele...
libarchive version commit 9693801580c0cf7c70e862d305270a16b52826a7 onwards (release v3.2.0 onwards) contains a CWE-20: Improper Input Validation vulnerability in WARC parser - libarchive/archive_read_support_format_warc.c, _warc_read() that can result in DoS - quasi-infinite run time and disk usage from tiny file. This attack appear to be exploitable via th
debian
CVE-2011-1778P4MEDIUMCVSS 6.8fixed in libarchive 2.8.5-5 (bookworm)2011
CVE-2011-1778 [MEDIUM] CVE-2011-1778: libarchive - Buffer overflow in libarchive through 2.8.5 allows remote attackers to cause a d...
Buffer overflow in libarchive through 2.8.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TAR archive.
Scope: local
bookworm: resolved (fixed in 2.8.5-5)
bullseye: resolved (fixed in 2.8.5-5)
forky: resolved (fixed in 2.8.5-5)
sid: resolved (fixed in 2.8.5-5)
trixie: resolved (fixed in 2.
debian
CVE-2019-1000020P4LOWCVSS 6.5fixed in libarchive 3.3.3-4 (bookworm)2019
CVE-2019-1000020 [MEDIUM] CVE-2019-1000020: libarchive - libarchive version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (vers...
libarchive version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (version v2.8.0 onwards) contains a CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ISO9660 parser, archive_read_support_format_iso9660.c, read_CE()/parse_rockridge() that can result in DoS by infinite loop. This attack appears to be exploitable via t
debian
CVE-2010-4666P4HIGHCVSS 7.5fixed in libarchive 3.0.4-2 (bookworm)2010
CVE-2010-4666 [HIGH] CVE-2010-4666: libarchive - Buffer overflow in libarchive 3.0 pre-release code allows remote attackers to ca...
Buffer overflow in libarchive 3.0 pre-release code allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CAB file, which is not properly handled during the reading of Huffman code data within LZX compressed data.
Scope: local
bookworm: resolved (fixed in 3.0.4-2)
bullseye: resolved (fixed in
debian
CVE-2019-1000019P4LOWCVSS 6.5fixed in libarchive 3.3.3-4 (bookworm)2019
CVE-2019-1000019 [MEDIUM] CVE-2019-1000019: libarchive - libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (rele...
libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) contains a CWE-125: Out-of-bounds Read vulnerability in 7zip decompression, archive_read_support_format_7zip.c, header_bytes() that can result in a crash (denial of service). This attack appears to be exploitable via the victim opening a specially crafted 7zi
debian
CVE-2018-1000879P4MEDIUMCVSS 6.5fixed in libarchive 3.3.3-2 (bookworm)2018
CVE-2018-1000879 [MEDIUM] CVE-2018-1000879: libarchive - libarchive version commit 379867ecb330b3a952fb7bfa7bffb7bbd5547205 onwards (rele...
libarchive version commit 379867ecb330b3a952fb7bfa7bffb7bbd5547205 onwards (release v3.3.0 onwards) contains a CWE-476: NULL Pointer Dereference vulnerability in ACL parser - libarchive/archive_acl.c, archive_acl_from_text_l() that can result in Crash/DoS. This attack appear to be exploitable via the victim must open a specially crafted archive file.
Scope:
debian
CVE-2021-36976P4MEDIUMCVSS 6.5fixed in libarchive 3.6.0-1 (bookworm)2021
CVE-2021-36976 [MEDIUM] CVE-2021-36976: libarchive - libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from ...
libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).
Scope: local
bookworm: resolved (fixed in 3.6.0-1)
bullseye: resolved (fixed in 3.4.3-2+deb11u2)
forky: resolved (fixed in 3.6.0-1)
sid: resolved (fixed in 3.6.0-1)
trixie: resolved (fixed in 3.6.0-1)
debian
CVE-2011-1779P4HIGHCVSS 7.5fixed in libarchive 3.0.4-2 (bookworm)2011
CVE-2011-1779 [HIGH] CVE-2011-1779: libarchive - Multiple use-after-free vulnerabilities in libarchive 2.8.4 and 2.8.5 allow remo...
Multiple use-after-free vulnerabilities in libarchive 2.8.4 and 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted (1) TAR archive or (2) ISO9660 image.
Scope: local
bookworm: resolved (fixed in 3.0.4-2)
bullseye: resolved (fixed in 3.0.4-2)
forky: resolved (fixed in 3.0.4-2)
sid: re
debian