First published: Mon Feb 24 2025(Updated: )
A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Libarchive | <=3.7.7 | |
Oracle Libarchive | <=3.7.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1632 is classified as problematic due to its potential to cause a null pointer dereference.
CVE-2025-1632 affects libarchive versions up to and including 3.7.7.
CVE-2025-1632 can be exploited locally through manipulation of the bsdunzip.c function.
To fix CVE-2025-1632, update libarchive to a version newer than 3.7.7.
A null pointer dereference in the context of CVE-2025-1632 refers to the program attempting to access memory that hasn't been allocated, which leads to application crashes.