src
src copied to clipboard
CVE-2025-25724 (Medium) detected in libarchivev3.7.7
CVE-2025-25724 - Medium Severity Vulnerability
Vulnerable Library - libarchivev3.7.7
Multi-format archive and compression library
Library home page: https://github.com/libarchive/libarchive.git
Found in base branch: master
Vulnerable Source Files (1)
/contrib/libarchive/tar/util.c
Vulnerability Details
list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.
Publish Date: 2025-03-02
URL: CVE-2025-25724
CVSS 3 Score Details (4.0)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: Low
- Availability Impact: Low
Step up your Open Source Security Game with Mend here