CVE-2025-1632

Description

A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information

Base Score
3.3
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
EPSS Score
Exploitation Probability
0.198

Associated Vulnerability

VulnerabilityOS Platform
SUSE-SU-2025:0985-1(Basesystem Module 15-SP6) libarchive13-debuginfo-3.7.2-150600.3.12.1.x86_64.rpmLinux
SUSE-SU-2025:0985-1(Basesystem Module 15-SP6) libarchive13-3.7.2-150600.3.12.1.x86_64.rpmLinux
SUSE-SU-2025:0985-1(Basesystem Module 15-SP6) libarchive-devel-3.7.2-150600.3.12.1.x86_64.rpmLinux
SUSE-SU-2025:0985-1(Basesystem Module 15-SP6) libarchive-debugsource-3.7.2-150600.3.12.1.x86_64.rpmLinux
SUSE-SU-2025:0985-1(Development Tools Module 15-SP6) bsdtar-debuginfo-3.7.2-150600.3.12.1.x86_64.rpmLinux
SUSE-SU-2025:0985-1(Development Tools Module 15-SP6) bsdtar-3.7.2-150600.3.12.1.x86_64.rpmLinux
Library to read/write archive files (USN-7454-1) libarchive-tools_3.4.0-2ubuntu1.5_i386.debLinux
Library to read/write archive files (USN-7454-1) libarchive-tools_3.6.0-1ubuntu1.4_amd64.debLinux
Library to read/write archive files (USN-7454-1) libarchive-tools_3.7.2-2ubuntu0.4_amd64.debLinux
Library to read/write archive files (USN-7454-1) libarchive-tools_3.7.2-2ubuntu0.4_i386.debLinux
Library to read/write archive files (USN-7454-1) libarchive-tools_3.7.4-1ubuntu0.2_amd64.debLinux
Library to read/write archive files (USN-7454-1) libarchive-tools_3.7.4-1ubuntu0.2_i386.debLinux
Library to read/write archive files (USN-7454-1) libarchive13_3.4.0-2ubuntu1.5_amd64.debLinux
Library to read/write archive files (USN-7454-1) libarchive13_3.4.0-2ubuntu1.5_i386.debLinux
Library to read/write archive files (USN-7454-1) libarchive13_3.6.0-1ubuntu1.4_amd64.debLinux
Library to read/write archive files (USN-7454-1) libarchive13t64_3.7.2-2ubuntu0.4_amd64.debLinux
Library to read/write archive files (USN-7454-1) libarchive13t64_3.7.4-1ubuntu0.2_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234