Out-of-Bounds Access Vulnerability in libarchive
CVE-2024-48958

7.8HIGH

Key Information:

Vendor

libarchive

Vendor
CVE Published:
10 October 2024

What is CVE-2024-48958?

A vulnerability exists in libarchive that allows for out-of-bounds access during the processing of crafted RAR archive files. The issue is triggered by the execute_filter_delta function in the archive_read_support_format_rar.c file, where the source pointer can exceed the destination pointer. This flaw impacts libarchive versions before 3.7.5, potentially allowing attackers to exploit affected systems if the crafted RAR files are opened.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-48958 : Out-of-Bounds Access Vulnerability in libarchive