Debian Libarchive vulnerabilities
75 known vulnerabilities affecting debian/libarchive.
Total CVEs
75
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH28MEDIUM31LOW15
Vulnerabilities
Page 4 of 4
CVE-2015-8915P4LOWCVSS 5.5fixed in libarchive 3.2.0-2 (bookworm)2015
CVE-2015-8915 [MEDIUM] CVE-2015-8915: libarchive - bsdcpio in libarchive before 3.2.0 allows remote attackers to cause a denial of ...
bsdcpio in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read and crash) via crafted cpio file.
Scope: local
bookworm: resolved (fixed in 3.2.0-2)
bullseye: resolved (fixed in 3.2.0-2)
forky: resolved (fixed in 3.2.0-2)
sid: resolved (fixed in 3.2.0-2)
trixie: resolved (fixed in 3.2.0-2)
debian
CVE-2015-8927P4MEDIUMCVSS 5.5fixed in libarchive 3.2.0-2 (bookworm)2015
CVE-2015-8927 [MEDIUM] CVE-2015-8927: libarchive - The trad_enc_decrypt_update function in archive_read_support_format_zip.c in lib...
The trad_enc_decrypt_update function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted zip file, related to reading the password.
Scope: local
bookworm: resolved (fixed in 3.2.0-2)
bullseye: resolved (fixed in 3.2.0-2)
forky: resolved (fixed in 3.2
debian
CVE-2015-8933P4MEDIUMCVSS 5.5fixed in libarchive 3.2.0-2 (bookworm)2015
CVE-2015-8933 [MEDIUM] CVE-2015-8933: libarchive - Integer overflow in the archive_read_format_tar_skip function in archive_read_su...
Integer overflow in the archive_read_format_tar_skip function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file.
Scope: local
bookworm: resolved (fixed in 3.2.0-2)
bullseye: resolved (fixed in 3.2.0-2)
forky: resolved (fixed in 3.2.0-2)
sid: resolved (fixed in 3.2.0-
debian
CVE-2016-10349P4MEDIUMCVSS 5.5fixed in libarchive 3.2.2-3.1 (bookworm)2016
CVE-2016-10349 [MEDIUM] CVE-2016-10349: libarchive - The archive_le32dec function in archive_endian.h in libarchive 3.2.2 allows remo...
The archive_le32dec function in archive_endian.h in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
Scope: local
bookworm: resolved (fixed in 3.2.2-3.1)
bullseye: resolved (fixed in 3.2.2-3.1)
forky: resolved (fixed in 3.2.2-3.1)
sid: resolved (fixed in 3.2.2-3.1)
trix
debian
CVE-2016-10350P4MEDIUMCVSS 5.5fixed in libarchive 3.2.2-3.1 (bookworm)2016
CVE-2016-10350 [MEDIUM] CVE-2016-10350: libarchive - The archive_read_format_cab_read_header function in archive_read_support_format_...
The archive_read_format_cab_read_header function in archive_read_support_format_cab.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
Scope: local
bookworm: resolved (fixed in 3.2.2-3.1)
bullseye: resolved (fixed in 3.2.2-3.1)
forky: resolved (fixed in 3.2.2-3.1)
si
debian
CVE-2025-60753P4LOWCVSS 5.5fixed in libarchive 3.8.4-1 (forky)2025
CVE-2025-60753 [MEDIUM] CVE-2025-60753: libarchive - An issue was discovered in libarchive bsdtar before version 3.8.1 in function ap...
An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 3.8.4-1)
sid: resolved (fixed in 3
debian
CVE-2025-5917P4LOWCVSS 2.8fixed in libarchive 3.6.2-1+deb12u3 (bookworm)2025
CVE-2025-5917 [LOW] CVE-2025-5917: libarchive - A vulnerability has been identified in the libarchive library. This flaw involve...
A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be l
debian
CVE-2016-10209P4LOWCVSS 5.5fixed in libarchive 3.2.2-3.1 (bookworm)2016
CVE-2016-10209 [MEDIUM] CVE-2016-10209: libarchive - The archive_wstring_append_from_mbs function in archive_string.c in libarchive 3...
The archive_wstring_append_from_mbs function in archive_string.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive file.
Scope: local
bookworm: resolved (fixed in 3.2.2-3.1)
bullseye: resolved (fixed in 3.2.2-3.1)
forky: resolved (fixed in 3.2.2-3.1)
sid: resolved (fix
debian
CVE-2015-8929P4MEDIUMCVSS 5.5fixed in libarchive 3.2.0-2 (bookworm)2015
CVE-2015-8929 [MEDIUM] CVE-2015-8929: libarchive - Memory leak in the __archive_read_get_extract function in archive_read_extract2....
Memory leak in the __archive_read_get_extract function in archive_read_extract2.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service via a tar file.
Scope: local
bookworm: resolved (fixed in 3.2.0-2)
bullseye: resolved (fixed in 3.2.0-2)
forky: resolved (fixed in 3.2.0-2)
sid: resolved (fixed in 3.2.0-2)
trixie: resolved (fixed in 3.2
debian
CVE-2019-19221P4MEDIUMCVSS 5.5fixed in libarchive 3.4.2-1 (bookworm)2019
CVE-2019-19221 [MEDIUM] CVE-2019-19221: libarchive - In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an ...
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.
Scope: local
bookworm: resolved (fixed in 3.4.2-1)
bullseye: resolved (fixed in 3.4.2-1)
forky: resolved (fixed in 3.4.2-1)
sid: resolved (fixed in 3.4.2-1)
trixie:
debian
CVE-2006-5680P4LOWCVSS 5.0fixed in libarchive 1.3.1-1 (bookworm)2006
CVE-2006-5680 [MEDIUM] CVE-2006-5680: libarchive - The libarchive library in FreeBSD 6-STABLE after 2006-09-05 and before 2006-11-0...
The libarchive library in FreeBSD 6-STABLE after 2006-09-05 and before 2006-11-08 allows context-dependent attackers to cause a denial of service (CPU consumption) via a malformed archive that causes libarchive to skip a region past the actual end of the archive, which triggers an infinite loop that attempts to read more data.
Scope: local
bookworm: resolved (fix
debian
CVE-2016-7166P4MEDIUMCVSS 5.5fixed in libarchive 3.2.0-2 (bookworm)2016
CVE-2016-7166 [MEDIUM] CVE-2016-7166: libarchive - libarchive before 3.2.0 does not limit the number of recursive decompressions, w...
libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip file.
Scope: local
bookworm: resolved (fixed in 3.2.0-2)
bullseye: resolved (fixed in 3.2.0-2)
forky: resolved (fixed in 3.2.0-2)
sid: resolved (fixed in 3.2.0-2)
tr
debian
CVE-2024-26256HIGHCVSS 7.8fixed in libarchive 3.6.2-1+deb12u1 (bookworm)2024
CVE-2024-26256 [HIGH] CVE-2024-26256: libarchive - Libarchive Remote Code Execution Vulnerability
Libarchive Remote Code Execution Vulnerability
Scope: local
bookworm: resolved (fixed in 3.6.2-1+deb12u1)
bullseye: resolved
forky: resolved (fixed in 3.7.2-2.1)
sid: resolved (fixed in 3.7.2-2.1)
trixie: resolved (fixed in 3.7.2-2.1)
debian
CVE-2007-3645P4LOWCVSS 4.3fixed in libarchive 2.2.4-1 (bookworm)2007
CVE-2007-3645 [MEDIUM] CVE-2007-3645: libarchive - archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assiste...
archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (crash) via (1) an end-of-file condition within a tar header that follows a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive, which results in a NULL pointer dereference, a different issue t
debian
CVE-2007-3644P4LOWCVSS 4.3fixed in libarchive 2.2.4-1 (bookworm)2007
CVE-2007-3644 [MEDIUM] CVE-2007-3644: libarchive - archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assiste...
archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (infinite loop) via (1) an end-of-file condition within a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive.
Scope: local
bookworm: resolved (fixed in 2.2.4-1)
bullseye: resolved (fixed in 2.
debian
← Previous4 / 4