THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)

Ok

PUBLISHED

CVE-2024-37407

Assigner:mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca)
Reserved:2024-06-08
Published:2024-06-08
Updated:2024-06-08

Description

Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled. This occurs in slurp_central_directory in archive_read_support_format_zip.c.

References

https://github.com/libarchive/libarchive/pull/2145

https://github.com/libarchive/libarchive/commit/b6a979481b7d77c12fa17bbed94576b63bbcb0c0

https://github.com/libarchive/libarchive/releases/tag/v3.7.4

cve.org CVE-2024-37407

nvd.nist.gov CVE-2024-37407

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-37407