Description

Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled. This occurs in slurp_central_directory in archive_read_support_format_zip.c.

INFO

Published Date :

2024-06-08T00:00:00.000Z

Last Modified :

2025-03-14T16:00:17.183Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2024-37407 vulnerability.

Vendors Products
Libarchive
  • Libarchive

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact