We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-37407



Description

Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled. This occurs in slurp_central_directory in archive_read_support_format_zip.c.

Reserved 2024-06-08 | Published 2024-06-08 | Updated 2025-03-14 | Assigner mitre

References

github.com/libarchive/libarchive/pull/2145

github.com/...ommit/b6a979481b7d77c12fa17bbed94576b63bbcb0c0

github.com/libarchive/libarchive/releases/tag/v3.7.4

cve.org (CVE-2024-37407)

nvd.nist.gov (CVE-2024-37407)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-37407

Support options

Helpdesk Chat, Email, Knowledgebase