Out-of-Bounds Access in libarchive's archive_read_support_format_rar.c Through Src Movement
CVE-2024-48957

7.8HIGH

Key Information:

Vendor

libarchive

Vendor
CVE Published:
10 October 2024

What is CVE-2024-48957?

The execute_filter_audio function in archive_read_support_format_rar.c within Libarchive prior to version 3.7.5 is vulnerable to out-of-bounds access. This vulnerability can be triggered by a maliciously crafted archive file, which may lead the 'src' pointer to surpass the 'dst' pointer bounds, potentially resulting in unexpected behavior, memory corruption, or remote code execution opportunities. Users and developers relying on affected versions of Libarchive should assess their systems and upgrade to the patched version 3.7.5 or later to mitigate potential security threats.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-48957 : Out-of-Bounds Access in libarchive's archive_read_support_format_rar.c Through Src Movement