First published: Thu Oct 10 2024(Updated: )
execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libarchive | <=3.6.2-1+deb12u1<=3.7.4-1 | 3.4.3-2+deb11u1 |
libarchive | >=3.6.0<3.7.5 | |
libarchive | <3.7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-48958 is classified as a medium severity vulnerability due to its potential for out-of-bounds access.
To mitigate CVE-2024-48958, update libarchive to version 3.7.5 or later.
CVE-2024-48958 could allow attackers to exploit out-of-bounds access, potentially leading to data corruption or arbitrary code execution.
CVE-2024-48958 affects libarchive versions prior to 3.7.5, including all versions from 3.6.0 up to 3.7.4.
CVE-2024-48958 is particularly concerning for systems that handle untrusted RAR archive files.