REDHAT-BUG-2370874: Low severity Libarchive libarchive vulnerability
Published Jun 6, 2025
·Updated
In libarchive before 3.8.0, an off by one miscalculation of prefixes and suffixes for file names may lead to a 1 byte write overflow.
Affected Software
1 affected component
Libarchive libarchive<3.8.0
Event History
Jun 6, 2025
Data Sourced
via Red Hat·07:26 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2370874?
The severity of REDHAT-BUG-2370874 is considered to be high due to the potential for a 1 byte write overflow.
2
How do I fix REDHAT-BUG-2370874?
To fix REDHAT-BUG-2370874, upgrade to libarchive version 3.8.0 or later.
3
What systems are affected by REDHAT-BUG-2370874?
REDHAT-BUG-2370874 affects all systems using libarchive versions prior to 3.8.0.
4
What types of vulnerabilities are associated with REDHAT-BUG-2370874?
REDHAT-BUG-2370874 is associated with off-by-one errors and buffer overflow vulnerabilities.
5
Is there a workaround for REDHAT-BUG-2370874?
There is no recommended workaround for REDHAT-BUG-2370874; upgrading is the best approach.