libarchive through 3.7.7 has a heap-based buffer over...
Moderate severity
Unreviewed
Published
Feb 16, 2025
to the GitHub Advisory Database
•
Updated Feb 16, 2025
Description
Published by the National Vulnerability Database
Feb 16, 2025
Published to the GitHub Advisory Database
Feb 16, 2025
Last updated
Feb 16, 2025
libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.
References