src
src copied to clipboard
CVE-2025-60753 (Medium) detected in libarchivev3.8.1
CVE-2025-60753 - Medium Severity Vulnerability
Vulnerable Library - libarchivev3.8.1
Multi-format archive and compression library
Library home page: https://github.com/libarchive/libarchive.git
Found in HEAD commit: 816463d989cc5839c1cca2efb5bf2503408507fb
Found in base branch: master
Vulnerable Source Files (1)
/contrib/libarchive/tar/subst.c
Vulnerability Details
An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).
Publish Date: 2025-11-05
URL: CVE-2025-60753
CVSS 3 Score Details (5.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
Step up your Open Source Security Game with Mend here