https://seclists.org/oss-sec/2025/q2/66: libarchive 3.7.8 fixed CVE-2024-57970, CVE-2025-1632, & CVE-2025-25724
Published Apr 18, 2025
·Updated
Affected Software
1 affected component
Libarchive libarchive
Frequently Asked Questions
1
What is the severity of CVE-2024-57970?
CVE-2024-57970 is classified as a medium severity vulnerability affecting the tar reader in Libarchive.
2
How do I fix CVE-2024-57970?
To fix CVE-2024-57970, upgrade to Libarchive version 3.7.8 or later.
3
What is the impact of CVE-2025-1632?
CVE-2025-1632 can lead to a null pointer dereference, potentially causing application crashes.
4
What versions are affected by CVE-2025-25724?
CVE-2025-25724 affects versions of Libarchive prior to 3.7.8.
5
How do I ensure my libarchive installation is secure?
To ensure security, always keep your Libarchive installation updated to the latest version.