First published: Tue Nov 22 2022(Updated: )
In libarchive 3.6.1, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference or, in some cases, even arbitrary code execution. Upstream patch: <a href="https://github.com/libarchive/libarchive/commit/fd180c36036df7181a64931264732a10ad8cd024">https://github.com/libarchive/libarchive/commit/fd180c36036df7181a64931264732a10ad8cd024</a>
Affected Software | Affected Version | How to fix |
---|---|---|
libarchive |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.