Vulnerabilities in Libarchive leading to memory corruption

The Libarchive library, which provides functions for working with various archive formats and compressed files, has identified vulnerabilities that lead to buffer overflows when processing specially crafted RAR archives. The vulnerabilities exist in the functions execute_filter_audio (CVE-2024-48957) and execute_filter_delta (CVE-2024-48958) and are caused by the lack of checks that the 'src' block may overlap with the 'dst' block in corrupted archives.

The vulnerabilities have been addressed in Libarchive version 3.7.5, which also fixes over a dozen bugs leading to buffer overflows, dereferencing freed memory, or integer overflows when processing files in cpio, lzop, rpm, zip, uu, and rar formats. The fixes are marked as security issues but without assigned CVE identifiers. It is still unclear whether these issues can be exploited to execute code while processing specially crafted files.

Libarchive is used as a dependency in many popular packages, such as smbclient, flatpak, appstream, libappimage, dpdk, cmake, rpm, nix, pacman, elfutils, unrar, claws-mail, ark, epiphany, evince, vagrant, vlc, mpv, gvfs, fwupd, systemd (optional), and file-roller (archive manager in GNOME). Updates for distributions can be tracked on the following pages: Debian, Ubuntu, RHEL, SUSE/openSUSE, Fedora, Arch, FreeBSD.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster