First published: Sun Feb 16 2025(Updated: )
libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libarchive | <=3.7.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-57970 is classified as a moderate vulnerability due to the potential for heap-based buffer over-reads.
To fix CVE-2024-57970, upgrade libarchive to version 3.7.8 or later.
CVE-2024-57970 is caused by mishandling truncation during the processing of GNU long linknames in TAR archives.
CVE-2024-57970 affects libarchive versions up to and including 3.7.7.
To determine if your system is vulnerable to CVE-2024-57970, check if you are using libarchive version 3.7.7 or earlier.