Out-of-Bounds Access in libarchive's archive_read_support_format_rar.c Through Src Movement
CVE-2024-48957
7.8HIGH
What is CVE-2024-48957?
The execute_filter_audio function in archive_read_support_format_rar.c within Libarchive prior to version 3.7.5 is vulnerable to out-of-bounds access. This vulnerability can be triggered by a maliciously crafted archive file, which may lead the 'src' pointer to surpass the 'dst' pointer bounds, potentially resulting in unexpected behavior, memory corruption, or remote code execution opportunities. Users and developers relying on affected versions of Libarchive should assess their systems and upgrade to the patched version 3.7.5 or later to mitigate potential security threats.