Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of service (crash) via unspecified vectors, which triggers an improper conversion between unsigned and signed types, leading to a buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libarchive | Aug 30, 2017 | Sep 30, 2013 |
| Debian | — | Upgrade libarchive | Jul 30, 2024 | Sep 30, 2013 |
| Freebsd | — | Upgrade FreeBSDUpgrade libarchive | Dec 10, 2025 | Jan 18, 2016 |
| Gentoo Linux | — | Upgrade app-arch/libarchive. | Oct 30, 2017 | Sep 30, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 25, 2013 |
| Suse | — | Upgrade libarchiveUpgrade libarchive13-32bitUpgrade libarchive13Upgrade libarchive-develUpgrade bsdtar | Jun 4, 2015 | Sep 30, 2013 |
| Ubuntu | — | Upgrade bsdcpioUpgrade libarchive12Upgrade libarchive13 | Nov 8, 2024 | Sep 30, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub