CVE-2007-3641
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
archive_read_support_format_tar.c in libarchive before 2.2.4 does not properly compute the length of a certain buffer when processing a malformed pax extension header, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PAX or (2) TAR archive that triggers a buffer overflow.
El archive_read_support_format_tar.c en el libarchive anterior al 2.2.4 no calcula adecuadamente la longitud de ciertos búfers cuando está procesando cabeceras de la extensión pax mal formadas, lo que permite a atacantes con la intervención del usuario provocar una denegación de servicio (caída) y, posiblemente, ejecutar código de su elección a través de archivos (1) PAX o (2) TAR que disparen desbordamientos de búfer.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-07-09 CVE Reserved
- 2007-07-13 CVE Published
- 2024-08-07 CVE Updated
- 2024-09-08 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (16)
URL | Tag | Source |
---|---|---|
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=432924 | X_refsource_confirm | |
http://osvdb.org/38092 | Vdb Entry | |
http://people.freebsd.org/~kientzle/libarchive | X_refsource_confirm | |
http://secunia.com/advisories/26355 | Third Party Advisory | |
http://secunia.com/advisories/28377 | Third Party Advisory | |
http://www.securitytracker.com/id?1018379 | Vdb Entry | |
http://www.vupen.com/english/advisories/2007/2521 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/35405 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/26050 | 2017-07-29 | |
http://secunia.com/advisories/26062 | 2017-07-29 | |
http://security.freebsd.org/patches/SA-07:05/libarchive.patch | 2017-07-29 | |
http://www.securityfocus.com/bid/24885 | 2017-07-29 |
URL | Date | SRC |
---|---|---|
http://security.freebsd.org/advisories/FreeBSD-SA-07:05.libarchive.asc | 2017-07-29 | |
http://security.gentoo.org/glsa/glsa-200708-03.xml | 2017-07-29 | |
http://www.debian.org/security/2008/dsa-1455 | 2017-07-29 | |
http://www.novell.com/linux/security/advisories/2007_15_sr.html | 2017-07-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Freebsd Search vendor "Freebsd" | Libarchive Search vendor "Freebsd" for product "Libarchive" | <= 2.2.3 Search vendor "Freebsd" for product "Libarchive" and version " <= 2.2.3" | - |
Affected
|