Intel

AIKIDO-2024-10274

libarchive.libarchive is vulnerable to Remote Code Execution (RCE)

Remote Code Execution (RCE)CVE-2024-20696 Published Sep 16, 2024

73

High Risk

This Affects:

c++libarchive.libarchive
3.1.0 - 3.7.4
Fixed in 3.7.5
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to Remote Code Execution (RCE). The copy_..._to_unp functions are not properly protected from excessively large or small lengths, allowing an attacker to exploit this flaw and potentially execute arbitrary code.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

libarchive.libarchive is vulnerable to Remote Code Execution (RCE) in versions 3.1.0 - 3.7.4.

How to fix this

Upgrade the libarchive.libarchive library to the patch version.