cbcvebase.

Debian Libarchive vulnerabilities

75 known vulnerabilities affecting debian/libarchive.

Total CVEs
75
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH28MEDIUM31LOW15

Vulnerabilities

Page 4 of 4
CVE-2015-8915P4LOWCVSS 5.5fixed in libarchive 3.2.0-2 (bookworm)2015
CVE-2015-8915 [MEDIUM] CVE-2015-8915: libarchive - bsdcpio in libarchive before 3.2.0 allows remote attackers to cause a denial of ... bsdcpio in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read and crash) via crafted cpio file. Scope: local bookworm: resolved (fixed in 3.2.0-2) bullseye: resolved (fixed in 3.2.0-2) forky: resolved (fixed in 3.2.0-2) sid: resolved (fixed in 3.2.0-2) trixie: resolved (fixed in 3.2.0-2)
debian
CVE-2015-8927P4MEDIUMCVSS 5.5fixed in libarchive 3.2.0-2 (bookworm)2015
CVE-2015-8927 [MEDIUM] CVE-2015-8927: libarchive - The trad_enc_decrypt_update function in archive_read_support_format_zip.c in lib... The trad_enc_decrypt_update function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted zip file, related to reading the password. Scope: local bookworm: resolved (fixed in 3.2.0-2) bullseye: resolved (fixed in 3.2.0-2) forky: resolved (fixed in 3.2
debian
CVE-2015-8933P4MEDIUMCVSS 5.5fixed in libarchive 3.2.0-2 (bookworm)2015
CVE-2015-8933 [MEDIUM] CVE-2015-8933: libarchive - Integer overflow in the archive_read_format_tar_skip function in archive_read_su... Integer overflow in the archive_read_format_tar_skip function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file. Scope: local bookworm: resolved (fixed in 3.2.0-2) bullseye: resolved (fixed in 3.2.0-2) forky: resolved (fixed in 3.2.0-2) sid: resolved (fixed in 3.2.0-
debian
CVE-2016-10349P4MEDIUMCVSS 5.5fixed in libarchive 3.2.2-3.1 (bookworm)2016
CVE-2016-10349 [MEDIUM] CVE-2016-10349: libarchive - The archive_le32dec function in archive_endian.h in libarchive 3.2.2 allows remo... The archive_le32dec function in archive_endian.h in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file. Scope: local bookworm: resolved (fixed in 3.2.2-3.1) bullseye: resolved (fixed in 3.2.2-3.1) forky: resolved (fixed in 3.2.2-3.1) sid: resolved (fixed in 3.2.2-3.1) trix
debian
CVE-2016-10350P4MEDIUMCVSS 5.5fixed in libarchive 3.2.2-3.1 (bookworm)2016
CVE-2016-10350 [MEDIUM] CVE-2016-10350: libarchive - The archive_read_format_cab_read_header function in archive_read_support_format_... The archive_read_format_cab_read_header function in archive_read_support_format_cab.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file. Scope: local bookworm: resolved (fixed in 3.2.2-3.1) bullseye: resolved (fixed in 3.2.2-3.1) forky: resolved (fixed in 3.2.2-3.1) si
debian
CVE-2025-60753P4LOWCVSS 5.5fixed in libarchive 3.8.4-1 (forky)2025
CVE-2025-60753 [MEDIUM] CVE-2025-60753: libarchive - An issue was discovered in libarchive bsdtar before version 3.8.1 in function ap... An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash). Scope: local bookworm: open bullseye: open forky: resolved (fixed in 3.8.4-1) sid: resolved (fixed in 3
debian
CVE-2025-5917P4LOWCVSS 2.8fixed in libarchive 3.6.2-1+deb12u3 (bookworm)2025
CVE-2025-5917 [LOW] CVE-2025-5917: libarchive - A vulnerability has been identified in the libarchive library. This flaw involve... A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be l
debian
CVE-2016-10209P4LOWCVSS 5.5fixed in libarchive 3.2.2-3.1 (bookworm)2016
CVE-2016-10209 [MEDIUM] CVE-2016-10209: libarchive - The archive_wstring_append_from_mbs function in archive_string.c in libarchive 3... The archive_wstring_append_from_mbs function in archive_string.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive file. Scope: local bookworm: resolved (fixed in 3.2.2-3.1) bullseye: resolved (fixed in 3.2.2-3.1) forky: resolved (fixed in 3.2.2-3.1) sid: resolved (fix
debian
CVE-2015-8929P4MEDIUMCVSS 5.5fixed in libarchive 3.2.0-2 (bookworm)2015
CVE-2015-8929 [MEDIUM] CVE-2015-8929: libarchive - Memory leak in the __archive_read_get_extract function in archive_read_extract2.... Memory leak in the __archive_read_get_extract function in archive_read_extract2.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service via a tar file. Scope: local bookworm: resolved (fixed in 3.2.0-2) bullseye: resolved (fixed in 3.2.0-2) forky: resolved (fixed in 3.2.0-2) sid: resolved (fixed in 3.2.0-2) trixie: resolved (fixed in 3.2
debian
CVE-2019-19221P4MEDIUMCVSS 5.5fixed in libarchive 3.4.2-1 (bookworm)2019
CVE-2019-19221 [MEDIUM] CVE-2019-19221: libarchive - In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an ... In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive. Scope: local bookworm: resolved (fixed in 3.4.2-1) bullseye: resolved (fixed in 3.4.2-1) forky: resolved (fixed in 3.4.2-1) sid: resolved (fixed in 3.4.2-1) trixie:
debian
CVE-2006-5680P4LOWCVSS 5.0fixed in libarchive 1.3.1-1 (bookworm)2006
CVE-2006-5680 [MEDIUM] CVE-2006-5680: libarchive - The libarchive library in FreeBSD 6-STABLE after 2006-09-05 and before 2006-11-0... The libarchive library in FreeBSD 6-STABLE after 2006-09-05 and before 2006-11-08 allows context-dependent attackers to cause a denial of service (CPU consumption) via a malformed archive that causes libarchive to skip a region past the actual end of the archive, which triggers an infinite loop that attempts to read more data. Scope: local bookworm: resolved (fix
debian
CVE-2016-7166P4MEDIUMCVSS 5.5fixed in libarchive 3.2.0-2 (bookworm)2016
CVE-2016-7166 [MEDIUM] CVE-2016-7166: libarchive - libarchive before 3.2.0 does not limit the number of recursive decompressions, w... libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip file. Scope: local bookworm: resolved (fixed in 3.2.0-2) bullseye: resolved (fixed in 3.2.0-2) forky: resolved (fixed in 3.2.0-2) sid: resolved (fixed in 3.2.0-2) tr
debian
CVE-2024-26256HIGHCVSS 7.8fixed in libarchive 3.6.2-1+deb12u1 (bookworm)2024
CVE-2024-26256 [HIGH] CVE-2024-26256: libarchive - Libarchive Remote Code Execution Vulnerability Libarchive Remote Code Execution Vulnerability Scope: local bookworm: resolved (fixed in 3.6.2-1+deb12u1) bullseye: resolved forky: resolved (fixed in 3.7.2-2.1) sid: resolved (fixed in 3.7.2-2.1) trixie: resolved (fixed in 3.7.2-2.1)
debian
CVE-2007-3645P4LOWCVSS 4.3fixed in libarchive 2.2.4-1 (bookworm)2007
CVE-2007-3645 [MEDIUM] CVE-2007-3645: libarchive - archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assiste... archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (crash) via (1) an end-of-file condition within a tar header that follows a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive, which results in a NULL pointer dereference, a different issue t
debian
CVE-2007-3644P4LOWCVSS 4.3fixed in libarchive 2.2.4-1 (bookworm)2007
CVE-2007-3644 [MEDIUM] CVE-2007-3644: libarchive - archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assiste... archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (infinite loop) via (1) an end-of-file condition within a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive. Scope: local bookworm: resolved (fixed in 2.2.4-1) bullseye: resolved (fixed in 2.
debian
Debian Libarchive vulnerabilities | cvebase