Insufficient UI Warning of Dangerous Operations in libarchive - #VU88217
Published: April 9, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to a confusing error message in libarchive when attempting to modify a directory without sufficient permissions. A remote attacker can trick the victim into extracting a specially crafted archive, which can have some security impact on the system.
Affected software
Slackware Linux
libarchive
Remediation
libarchive - update to 3.7.3