Denial of Service Vulnerability in libarchive TAR Utility
CVE-2025-25724
4MEDIUM
What is CVE-2025-25724?
The libarchive TAR utility contains a vulnerability in the list_item_verbose function located in tar/util.c. This flaw occurs due to the absence of checks on the return value of strftime, leading to potential denial of service scenarios or other unspecified impacts. When processing a crafted TAR archive with a verbose setting of 2, the utility may attempt to write to a 100-byte buffer that is inadequate for certain custom locales, resulting in unintended disruptions in service.
Affected Version(s)
libarchive 0 <= 3.7.7