Resource exhaustion in libarchive - #VU98562
Published: October 15, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when processing gzip archives. A remote attacker can pass a malformed gzip inside a gzip archive with an extremely large filename field and perform a denial of service (DoS) attack.
Affected software
Slackware Linux
libarchive
Remediation
libarchive - update to 3.7.7