Critical severity9.1NVD Advisory· Published Jun 8, 2024· Updated Jun 17, 2026
CVE-2024-37407
CVE-2024-37407
Description
Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled. This occurs in slurp_central_directory in archive_read_support_format_zip.c.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11cpe:2.3:a:libarchive:libarchive:3.7.3:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:libarchive:libarchive:3.7.3:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: <3.7.4
- osv-coords8 versionspkg:apk/chainguard/libarchivepkg:apk/chainguard/libarchive-devpkg:apk/chainguard/libarchive-docpkg:apk/chainguard/libarchive-toolspkg:apk/wolfi/libarchivepkg:apk/wolfi/libarchive-devpkg:apk/wolfi/libarchive-docpkg:apk/wolfi/libarchive-tools
< 3.7.4-r0+ 7 more
- (no CPE)range: < 3.7.4-r0
- (no CPE)range: < 3.7.4-r0
- (no CPE)range: < 3.7.4-r0
- (no CPE)range: < 3.7.4-r0
- (no CPE)range: < 3.7.4-r0
- (no CPE)range: < 3.7.4-r0
- (no CPE)range: < 3.7.4-r0
- (no CPE)range: < 3.7.4-r0
Patches
Vulnerability mechanics
References
3- github.com/libarchive/libarchive/releases/tag/v3.7.4nvdPatch
- github.com/libarchive/libarchive/pull/2145nvdExploitIssue Tracking
- github.com/libarchive/libarchive/commit/b6a979481b7d77c12fa17bbed94576b63bbcb0c0nvdIssue Tracking
News mentions
0No linked articles in our index yet.