CVE-2025-1632

A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc Exploit
https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc Exploit
https://vuldb.com/?ctiid.296619 Permissions Required VDB Entry
https://vuldb.com/?id.296619 Permissions Required VDB Entry
https://vuldb.com/?submit.496460 VDB Entry Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:*

History

25 Mar 2025, 15:41

Type Values Removed Values Added
References () https://vuldb.com/?id.296619 - () https://vuldb.com/?id.296619 - Permissions Required, VDB Entry
References () https://vuldb.com/?submit.496460 - () https://vuldb.com/?submit.496460 - VDB Entry, Exploit, Third Party Advisory
References () https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc - () https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc - Exploit
References () https://vuldb.com/?ctiid.296619 - () https://vuldb.com/?ctiid.296619 - Permissions Required, VDB Entry
CWE CWE-476
CPE cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:*
First Time Libarchive libarchive
Libarchive
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

24 Feb 2025, 15:15

Type Values Removed Values Added
CWE CWE-404
CWE-476
CVSS v2 : unknown
v3 : 3.3
v2 : unknown
v3 : unknown

24 Feb 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-24 14:15

Updated : 2025-03-25 15:41


NVD link : CVE-2025-1632

Mitre link : CVE-2025-1632


JSON object : View

Products Affected

libarchive

  • libarchive
CWE
CWE-476

NULL Pointer Dereference