libarchive.libarchive is vulnerable to NULL Pointer Dereference
55
Medium Risk
Affected versions of this package contain a flaw in archive_entry_acl_from_text_w where malformed ACL input may trigger a segmentation fault instead of returning ARCHIVE_WARN as specified by the API contract. The function fails to properly validate certain malformed ACL strings, leading to a null pointer dereference during parsing. An attacker able to supply crafted ACL metadata—such as through a malicious archive file processed by software relying on libarchive—could trigger a crash, resulting in a denial-of-service condition when the archive is parsed.
You are affected if you are using a version that falls within the vulnerable range.
libarchive.libarchive is vulnerable to NULL Pointer Dereference in versions 3.3.0 - 3.8.5.
Upgrade the libarchive.libarchive library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant