Debian Libarchive vulnerabilities
87 known vulnerabilities affecting debian/libarchive.
Total CVEs
87
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH30MEDIUM33LOW22
Vulnerabilities
Page 5 of 5
CVE-2011-1778MEDIUMCVSS 6.8fixed in libarchive 2.8.5-5 (bookworm)2011
CVE-2011-1778 [MEDIUM] CVE-2011-1778: libarchive - Buffer overflow in libarchive through 2.8.5 allows remote attackers to cause a d...
Buffer overflow in libarchive through 2.8.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TAR archive.
Scope: local
bookworm: resolved (fixed in 2.8.5-5)
bullseye: resolved (fixed in 2.8.5-5)
forky: resolved (fixed in 2.8.5-5)
sid: resolved (fixed in 2.8.5-5)
trixie: resolved (fixed in 2.
debian
CVE-2011-1777MEDIUMCVSS 6.8fixed in libarchive 2.8.5-5 (bookworm)2011
CVE-2011-1777 [MEDIUM] CVE-2011-1777: libarchive - Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functio...
Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functions in archive_read_support_format_iso9660.c in libarchive through 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ISO9660 image.
Scope: local
bookworm: resolved (fixed in 2.8.5-5)
bullseye: resolved (fixed
debian
CVE-2010-4666HIGHCVSS 7.5fixed in libarchive 3.0.4-2 (bookworm)2010
CVE-2010-4666 [HIGH] CVE-2010-4666: libarchive - Buffer overflow in libarchive 3.0 pre-release code allows remote attackers to ca...
Buffer overflow in libarchive 3.0 pre-release code allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CAB file, which is not properly handled during the reading of Huffman code data within LZX compressed data.
Scope: local
bookworm: resolved (fixed in 3.0.4-2)
bullseye: resolved (fixed in
debian
CVE-2007-3641LOWCVSS 9.3fixed in libarchive 2.2.4-1 (bookworm)2007
CVE-2007-3641 [CRITICAL] CVE-2007-3641: libarchive - archive_read_support_format_tar.c in libarchive before 2.2.4 does not properly c...
archive_read_support_format_tar.c in libarchive before 2.2.4 does not properly compute the length of a certain buffer when processing a malformed pax extension header, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PAX or (2) TAR archive that triggers a buffer overflow.
Scop
debian
CVE-2007-3644LOWCVSS 4.3fixed in libarchive 2.2.4-1 (bookworm)2007
CVE-2007-3644 [MEDIUM] CVE-2007-3644: libarchive - archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assiste...
archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (infinite loop) via (1) an end-of-file condition within a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive.
Scope: local
bookworm: resolved (fixed in 2.2.4-1)
bullseye: resolved (fixed in 2.
debian
CVE-2007-3645LOWCVSS 4.3fixed in libarchive 2.2.4-1 (bookworm)2007
CVE-2007-3645 [MEDIUM] CVE-2007-3645: libarchive - archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assiste...
archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (crash) via (1) an end-of-file condition within a tar header that follows a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive, which results in a NULL pointer dereference, a different issue t
debian
CVE-2006-5680LOWCVSS 5.0fixed in libarchive 1.3.1-1 (bookworm)2006
CVE-2006-5680 [MEDIUM] CVE-2006-5680: libarchive - The libarchive library in FreeBSD 6-STABLE after 2006-09-05 and before 2006-11-0...
The libarchive library in FreeBSD 6-STABLE after 2006-09-05 and before 2006-11-08 allows context-dependent attackers to cause a denial of service (CPU consumption) via a malformed archive that causes libarchive to skip a region past the actual end of the archive, which triggers an infinite loop that attempts to read more data.
Scope: local
bookworm: resolved (fix
debian
← Previous5 / 5