CVE-2025-1632

A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc Exploit
https://vuldb.com/?ctiid.296619 Permissions Required VDB Entry
https://vuldb.com/?id.296619 Permissions Required VDB Entry
https://vuldb.com/?submit.496460 VDB Entry Exploit Third Party Advisory
https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc Exploit
Configurations

Configuration 1 (hide)

cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-02-24 14:15

Updated : 2025-03-25 15:41


NVD link : CVE-2025-1632

Mitre link : CVE-2025-1632

CVE.ORG link : CVE-2025-1632


JSON object : View

Products Affected

libarchive

  • libarchive
CWE
CWE-404

Improper Resource Shutdown or Release

CWE-476

NULL Pointer Dereference