Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-5869 | list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale. |
Ubuntu USN |
USN-7454-1 | libarchive vulnerabilities |
Thu, 17 Jul 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Libarchive
Libarchive libarchive |
|
| CPEs | cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Libarchive
Libarchive libarchive |
Wed, 25 Jun 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:enterprise_linux:9 cpe:/o:redhat:enterprise_linux:9 |
Tue, 24 Jun 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| CPEs | cpe:/o:redhat:enterprise_linux:10.0 | |
| Vendors & Products |
Redhat
Redhat enterprise Linux |
Tue, 04 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Mar 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | libarchive: Buffer Overflow vulnerability in libarchive | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Sun, 02 Mar 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale. | |
| Weaknesses | CWE-252 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-04T19:00:41.262Z
Reserved: 2025-02-07T00:00:00.000Z
Link: CVE-2025-25724
Updated: 2025-03-04T19:00:36.589Z
Status : Analyzed
Published: 2025-03-02T02:15:36.603
Modified: 2025-07-17T15:56:36.083
Link: CVE-2025-25724
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN