First published: Sun Mar 02 2025(Updated: )
list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Libarchive | <3.7.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25724 has been classified as a medium severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2025-25724, upgrade to libarchive version 3.7.8 or later where the vulnerability is addressed.
CVE-2025-25724 can lead to a denial of service or other unspecified impacts when processing crafted TAR archives.
CVE-2025-25724 affects libarchive versions prior to 3.7.8.
Yes, CVE-2025-25724 can be exploited remotely if a vulnerable system processes a malicious TAR archive.