Denial of Service Vulnerability in libarchive Affecting Multiple Vendors
CVE-2007-3644

Currently unrated

Key Information:

Vendor

FreeBSD

Vendor
CVE Published:
14 July 2007

What is CVE-2007-3644?

A vulnerability in libarchive prior to version 2.2.4 can be exploited by remote attackers to induce a denial of service through an infinite loop. This occurs when a malicious PAX or TAR archive contains a malformed pax extension header or an end-of-file condition specifically within the pax extension. Users interacting with such archives could unknowingly trigger this vulnerability, leading to service interruption.

References

EPSS Score

13% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2007-3644 : Denial of Service Vulnerability in libarchive Affecting Multiple Vendors