CVE-2025-1632

A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc Exploit
https://vuldb.com/?ctiid.296619 Permissions Required VDB Entry
https://vuldb.com/?id.296619 Permissions Required VDB Entry
https://vuldb.com/?submit.496460 VDB Entry Exploit Third Party Advisory
https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc Exploit
Configurations

Configuration 1 (hide)

cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:*

History

25 Mar 2025, 15:41

Type Values Removed Values Added
References () https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc - () https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc - Exploit
References () https://vuldb.com/?ctiid.296619 - () https://vuldb.com/?ctiid.296619 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.296619 - () https://vuldb.com/?id.296619 - Permissions Required, VDB Entry
References () https://vuldb.com/?submit.496460 - () https://vuldb.com/?submit.496460 - VDB Entry, Exploit, Third Party Advisory
CPE cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:*
First Time Libarchive
Libarchive libarchive
Summary
  • (es) Se ha encontrado una vulnerabilidad en libarchive hasta la versión 3.7.7. Se ha clasificado como problemática. Afecta a la lista de funciones del archivo bsdunzip.c. La manipulación provoca la desreferenciación de puntero nulo. Es posible lanzar el ataque en el host local. El exploit se ha hecho público y puede utilizarse. Se contactó al proveedor con anticipación sobre esta revelación, pero no respondió de ninguna manera.

24 Feb 2025, 15:15

Type Values Removed Values Added
References () https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc - () https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc -

24 Feb 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-24 14:15

Updated : 2025-03-25 15:41


NVD link : CVE-2025-1632

Mitre link : CVE-2025-1632

CVE.ORG link : CVE-2025-1632


JSON object : View

Products Affected

libarchive

  • libarchive
CWE
CWE-404

Improper Resource Shutdown or Release

CWE-476

NULL Pointer Dereference