ZDI-24-1696: libarchive RAR File Parsing Integer Overflow Remote Code Execution Vulnerability
Published Dec 19, 2024
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of libarchive. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-20697.
Affected Software
1 affected component
Libarchive libarchive
Event History
Dec 19, 2024
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-24-1696?
The severity of ZDI-24-1696 is rated at 7.8 on the CVSS scale.
2
How do I fix ZDI-24-1696?
To fix ZDI-24-1696, you should update libarchive to the latest version that addresses this vulnerability.
3
What type of attack does ZDI-24-1696 facilitate?
ZDI-24-1696 facilitates remote code execution attacks on affected installations.
4
Is user interaction required to exploit ZDI-24-1696?
Yes, user interaction is required as the target must open a malicious file or visit a malicious webpage.
5
Which software is affected by ZDI-24-1696?
The affected software for ZDI-24-1696 is libarchive.