CVE-2024-57970: libarchive 3.7.8 fixed CVE-2024-57970, CVE-2025-1632, & CVE-2025-25724
Published Feb 16, 2025
·Updated
libarchive through 3.7.7 has a heap-based buffer over-read in headergnulonglink in archivereadsupportformattar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.
Affected Software
1 affected component
Libarchive libarchive<=3.7.7
Event History
Feb 16, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-57970?
CVE-2024-57970 is classified as a moderate vulnerability due to the potential for heap-based buffer over-reads.
2
How do I fix CVE-2024-57970?
To fix CVE-2024-57970, upgrade libarchive to version 3.7.8 or later.
3
What causes the CVE-2024-57970 vulnerability?
CVE-2024-57970 is caused by mishandling truncation during the processing of GNU long linknames in TAR archives.
4
Which versions of libarchive are affected by CVE-2024-57970?
CVE-2024-57970 affects libarchive versions up to and including 3.7.7.
5
How can I determine if my system is vulnerable to CVE-2024-57970?
To determine if your system is vulnerable to CVE-2024-57970, check if you are using libarchive version 3.7.7 or earlier.