Debian Libarchive vulnerabilities
75 known vulnerabilities affecting debian/libarchive.
Total CVEs
75
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH28MEDIUM31LOW15
Vulnerabilities
Page 3 of 4
CVE-2017-14501P4MEDIUMCVSS 6.5fixed in libarchive 3.2.2-4.2 (bookworm)2017
CVE-2017-14501 [MEDIUM] CVE-2017-14501: libarchive - An out-of-bounds read flaw exists in parse_file_info in archive_read_support_for...
An out-of-bounds read flaw exists in parse_file_info in archive_read_support_format_iso9660.c in libarchive 3.3.2 when extracting a specially crafted iso9660 iso file, related to archive_read_format_iso9660_read_header.
Scope: local
bookworm: resolved (fixed in 3.2.2-4.2)
bullseye: resolved (fixed in 3.2.2-4.2)
forky: resolved (fixed in 3.2.2-4.2)
sid: resolved
debian
CVE-2017-14503P4MEDIUMCVSS 6.5fixed in libarchive 3.2.2-4.1 (bookworm)2017
CVE-2017-14503 [MEDIUM] CVE-2017-14503: libarchive - libarchive 3.3.2 suffers from an out-of-bounds read within lha_read_data_none() ...
libarchive 3.3.2 suffers from an out-of-bounds read within lha_read_data_none() in archive_read_support_format_lha.c when extracting a specially crafted lha archive, related to lha_crc16.
Scope: local
bookworm: resolved (fixed in 3.2.2-4.1)
bullseye: resolved (fixed in 3.2.2-4.1)
forky: resolved (fixed in 3.2.2-4.1)
sid: resolved (fixed in 3.2.2-4.1)
trixie: re
debian
CVE-2017-14166P4MEDIUMCVSS 6.5fixed in libarchive 3.2.2-3.1 (bookworm)2017
CVE-2017-14166 [MEDIUM] CVE-2017-14166: libarchive - libarchive 3.3.2 allows remote attackers to cause a denial of service (xml_data ...
libarchive 3.3.2 allows remote attackers to cause a denial of service (xml_data heap-based buffer over-read and application crash) via a crafted xar archive, related to the mishandling of empty strings in the atol8 function in archive_read_support_format_xar.c.
Scope: local
bookworm: resolved (fixed in 3.2.2-3.1)
bullseye: resolved (fixed in 3.2.2-3.1)
forky: r
debian
CVE-2015-8916P4MEDIUMCVSS 6.5fixed in libarchive 3.2.0-2 (bookworm)2015
CVE-2015-8916 [MEDIUM] CVE-2015-8916: libarchive - bsdtar in libarchive before 3.2.0 returns a success code without filling the ent...
bsdtar in libarchive before 3.2.0 returns a success code without filling the entry when the header is a "split file in multivolume RAR," which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted rar file.
Scope: local
bookworm: resolved (fixed in 3.2.0-2)
bullseye: resolved (fixed in 3.2.0-2)
forky: resolved (fi
debian
CVE-2015-8923P4MEDIUMCVSS 6.5fixed in libarchive 3.2.0-2 (bookworm)2015
CVE-2015-8923 [MEDIUM] CVE-2015-8923: libarchive - The process_extra function in libarchive before 3.2.0 uses the size field and a ...
The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file.
Scope: local
bookworm: resolved (fixed in 3.2.0-2)
bullseye: resolved (fixed in 3.2.0-2)
forky: resolved (fixed in 3.2.0-2)
sid: resolved (fixed in 3.2.0-2)
trixie: r
debian
CVE-2025-5915P4MEDIUMCVSS 6.6fixed in libarchive 3.6.2-1+deb12u3 (bookworm)2025
CVE-2025-5915 [MEDIUM] CVE-2025-5915: libarchive - A vulnerability has been identified in the libarchive library. This flaw can lea...
A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of serv
debian
CVE-2013-0211P4MEDIUMCVSS 5.0fixed in libarchive 3.0.4-3 (bookworm)2013
CVE-2013-0211 [MEDIUM] CVE-2013-0211: libarchive - Integer signedness error in the archive_write_zip_data function in archive_write...
Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of service (crash) via unspecified vectors, which triggers an improper conversion between unsigned and signed types, leading to a buffer overflow.
S
debian
CVE-2025-5918P4LOWCVSS 3.9fixed in libarchive 3.4.3-2+deb11u3 (bullseye)2025
CVE-2025-5918 [LOW] CVE-2025-5918: libarchive - A vulnerability has been identified in the libarchive library. This flaw can be ...
A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.
Scope: local
bookworm:
debian
CVE-2016-5844P4MEDIUMCVSS 6.5fixed in libarchive 3.2.1-1 (bookworm)2016
CVE-2016-5844 [MEDIUM] CVE-2016-5844: libarchive - Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote atta...
Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a crafted ISO file.
Scope: local
bookworm: resolved (fixed in 3.2.1-1)
bullseye: resolved (fixed in 3.2.1-1)
forky: resolved (fixed in 3.2.1-1)
sid: resolved (fixed in 3.2.1-1)
trixie: resolved (fixed in 3.2.1-1)
debian
CVE-2015-8924P4MEDIUMCVSS 5.5fixed in libarchive 3.2.0-2 (bookworm)2015
CVE-2015-8924 [MEDIUM] CVE-2015-8924: libarchive - The archive_read_format_tar_read_header function in archive_read_support_format_...
The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tar file.
Scope: local
bookworm: resolved (fixed in 3.2.0-2)
bullseye: resolved (fixed in 3.2.0-2)
forky: resolved (fixed in 3.2.0-2)
sid: resolved (fixed in 3.2.0-
debian
CVE-2025-5916P4LOWCVSS 3.9fixed in libarchive 3.6.2-1+deb12u3 (bookworm)2025
CVE-2025-5916 [LOW] CVE-2025-5916: libarchive - A vulnerability has been identified in the libarchive library. This flaw involve...
A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corrupt
debian
CVE-2025-1632P4LOWCVSS 4.8fixed in libarchive 3.7.4-2 (forky)2025
CVE-2025-1632 [MEDIUM] CVE-2025-1632: libarchive - A vulnerability was found in libarchive up to 3.7.7. It has been classified as p...
A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclos
debian
CVE-2015-8926P4MEDIUMCVSS 5.5fixed in libarchive 3.2.0-2 (bookworm)2015
CVE-2015-8926 [MEDIUM] CVE-2015-8926: libarchive - The archive_read_format_rar_read_data function in archive_read_support_format_ra...
The archive_read_format_rar_read_data function in archive_read_support_format_rar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted rar archive.
Scope: local
bookworm: resolved (fixed in 3.2.0-2)
bullseye: resolved (fixed in 3.2.0-2)
forky: resolved (fixed in 3.2.0-2)
sid: resolved (fixed in 3.2.0-2)
trixie: r
debian
CVE-2015-8920P4MEDIUMCVSS 5.5fixed in libarchive 3.2.0-2 (bookworm)2015
CVE-2015-8920 [MEDIUM] CVE-2015-8920: libarchive - The _ar_read_header function in archive_read_support_format_ar.c in libarchive b...
The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds stack read) via a crafted ar file.
Scope: local
bookworm: resolved (fixed in 3.2.0-2)
bullseye: resolved (fixed in 3.2.0-2)
forky: resolved (fixed in 3.2.0-2)
sid: resolved (fixed in 3.2.0-2)
trixie: resol
debian
CVE-2015-8934P4MEDIUMCVSS 5.5fixed in libarchive 3.2.1-1 (bookworm)2015
CVE-2015-8934 [MEDIUM] CVE-2015-8934: libarchive - The copy_from_lzss_window function in archive_read_support_format_rar.c in libar...
The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted rar file.
Scope: local
bookworm: resolved (fixed in 3.2.1-1)
bullseye: resolved (fixed in 3.2.1-1)
forky: resolved (fixed in 3.2.1-1)
sid: resolved (fixed in 3.2.1-1)
t
debian
CVE-2015-8928P4MEDIUMCVSS 5.5fixed in libarchive 3.2.0-2 (bookworm)2015
CVE-2015-8928 [MEDIUM] CVE-2015-8928: libarchive - The process_add_entry function in archive_read_support_format_mtree.c in libarch...
The process_add_entry function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file.
Scope: local
bookworm: resolved (fixed in 3.2.0-2)
bullseye: resolved (fixed in 3.2.0-2)
forky: resolved (fixed in 3.2.0-2)
sid: resolved (fixed in 3.2.0-2)
trixie: res
debian
CVE-2015-8925P4MEDIUMCVSS 5.5fixed in libarchive 3.2.0-2 (bookworm)2015
CVE-2015-8925 [MEDIUM] CVE-2015-8925: libarchive - The readline function in archive_read_support_format_mtree.c in libarchive befor...
The readline function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read) via a crafted mtree file, related to newline parsing.
Scope: local
bookworm: resolved (fixed in 3.2.0-2)
bullseye: resolved (fixed in 3.2.0-2)
forky: resolved (fixed in 3.2.0-2)
sid: resolved (fixed in 3.2.0-2
debian
CVE-2015-8932P4MEDIUMCVSS 5.5fixed in libarchive 3.2.0-2 (bookworm)2015
CVE-2015-8932 [MEDIUM] CVE-2015-8932: libarchive - The compress_bidder_init function in archive_read_support_filter_compress.c in l...
The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left shift.
Scope: local
bookworm: resolved (fixed in 3.2.0-2)
bullseye: resolved (fixed in 3.2.0-2)
forky: resolved (fixed in 3.2.0-2)
sid: resolved (
debian
CVE-2015-8922P4MEDIUMCVSS 5.5fixed in libarchive 3.2.0-2 (bookworm)2015
CVE-2015-8922 [MEDIUM] CVE-2015-8922: libarchive - The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive...
The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted 7z file, related to the _7z_folder struct.
Scope: local
bookworm: resolved (fixed in 3.2.0-2)
bullseye: resolved (fixed in 3.2.0-2)
forky: resolved (fixed in 3.2.0-2)
debian
CVE-2016-8688P4MEDIUMCVSS 5.5fixed in libarchive 3.2.1-5 (bookworm)2016
CVE-2016-8688 [MEDIUM] CVE-2016-8688: libarchive - The mtree bidder in libarchive 3.2.1 does not keep track of line sizes when exte...
The mtree bidder in libarchive 3.2.1 does not keep track of line sizes when extending the read-ahead, which allows remote attackers to cause a denial of service (crash) via a crafted file, which triggers an invalid read in the (1) detect_form or (2) bid_entry function in libarchive/archive_read_support_format_mtree.c.
Scope: local
bookworm: resolved (fixed in 3.2
debian