Unrated severityNVD Advisory· Published Jun 8, 2024· Updated Mar 14, 2025
CVE-2024-37407
CVE-2024-37407
Description
Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled. This occurs in slurp_central_directory in archive_read_support_format_zip.c.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10(expand)+ 1 more
- (no CPE)
- (no CPE)range: <3.7.4
- osv-coords8 versionspkg:apk/chainguard/libarchivepkg:apk/chainguard/libarchive-devpkg:apk/chainguard/libarchive-docpkg:apk/chainguard/libarchive-toolspkg:apk/wolfi/libarchivepkg:apk/wolfi/libarchive-devpkg:apk/wolfi/libarchive-docpkg:apk/wolfi/libarchive-tools
< 3.7.4-r0+ 7 more
- (no CPE)range: < 3.7.4-r0
- (no CPE)range: < 3.7.4-r0
- (no CPE)range: < 3.7.4-r0
- (no CPE)range: < 3.7.4-r0
- (no CPE)range: < 3.7.4-r0
- (no CPE)range: < 3.7.4-r0
- (no CPE)range: < 3.7.4-r0
- (no CPE)range: < 3.7.4-r0
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.