Msrc Azl3 Libarchive 3.7.7-3 On Azure Linux 3.0 vulnerabilities

6 known vulnerabilities affecting msrc/azl3_libarchive_3.7.7-3_on_azure_linux_3.0.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM1LOW5

Vulnerabilities

Page 1 of 1
CVE-2025-60753MEDIUMCVSS 5.52025-11-11
CVE-2025-60753 [MEDIUM] CWE-400 An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allo An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash). Marine
msrc
CVE-2025-5916LOWCVSS 3.92025-06-10
CVE-2025-5916 [LOW] CWE-190 Libarchive: integer overflow while reading warc files at archive_read_support_format_warc.c Libarchive: integer overflow while reading warc files at archive_read_support_format_warc.c FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most rec
msrc
CVE-2025-5917LOWCVSS 2.82025-06-10
CVE-2025-5917 [LOW] CWE-787 Libarchive: off by one error in build_ustar_entry_name() at archive_write_set_format_pax.c Libarchive: off by one error in build_ustar_entry_name() at archive_write_set_format_pax.c FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recen
msrc
CVE-2025-5915LOWCVSS 3.92025-06-10
CVE-2025-5915 [MEDIUM] CWE-122 Libarchive: heap buffer over read in copy_from_lzss_window() at archive_read_support_format_rar.c Libarchive: heap buffer over read in copy_from_lzss_window() at archive_read_support_format_rar.c FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date wi
msrc
CVE-2025-5914LOWCVSS 3.92025-06-10
CVE-2025-5914 [HIGH] CWE-415 Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date
msrc
CVE-2025-5918LOWCVSS 3.92025-06-10
CVE-2025-5918 [LOW] CWE-125 Libarchive: reading past eof may be triggered for piped file streams Libarchive: reading past eof may be triggered for piped file streams FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open sourc
msrc