First published: Thu Oct 10 2024(Updated: )
execute_filter_audio in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Libarchive | >=3.6.0<3.7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-48957 has a medium severity level due to the potential for out-of-bounds access.
To mitigate CVE-2024-48957, upgrade to libarchive version 3.7.5 or later.
CVE-2024-48957 affects applications that utilize libarchive versions prior to 3.7.5 for processing RAR archive files.
Yes, CVE-2024-48957 can potentially be exploited by an attacker through a crafted archive file.
CVE-2024-48957 is associated with the execute_filter_audio function in archive_read_support_format_rar.c in libarchive.