CVE-2024-57970
EUVD-2024-5387016.02.2025, 04:15
libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| libarchive | libarchive | 𝑥 ≤ 3.7.7 | CNA |
Debian Releases
Ubuntu Releases
Common Weakness Enumeration