ZDI-24-1698: libarchive run_filters Heap-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of libarchive. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-26256.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1698?
The severity of ZDI-24-1698 is rated at 7.8 on the CVSS scale, indicating it is a high-risk vulnerability.
How can I fix ZDI-24-1698?
To fix ZDI-24-1698, you should update libarchive to the latest version where this vulnerability has been addressed.
What are the potential impacts of ZDI-24-1698?
ZDI-24-1698 can lead to remote code execution, allowing attackers to run arbitrary code on affected systems.
Which versions of libarchive are affected by ZDI-24-1698?
All versions of libarchive that are prior to the patch release addressing ZDI-24-1698 are vulnerable.
Is user interaction required to exploit ZDI-24-1698?
Yes, interaction with the libarchive library is required to exploit this vulnerability.