CVE-2024-26256
high · 7.8Libarchive Remote Code Execution Vulnerability
7.8
CVSS
84.8%
EPSS (exploit prob.)
100th
EPSS percentile
2024-04-09
Published
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-122CWE-787
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| libarchive | libarchive | < 3.7.4 |
| fedoraproject | fedora | 39 |
| fedoraproject | fedora | 40 |
| microsoft | windows_11_22h2 | < 10.0.22621.3447 |
| microsoft | windows_11_23h2 | < 10.0.22631.3447 |
| microsoft | windows_server_2022_23h2 | < 10.0.25398.830 |
Check a specific version with /api/v1/cve/match.
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26256
- http://www.openwall.com/lists/oss-security/2024/06/04/2
- http://www.openwall.com/lists/oss-security/2024/06/05/1
- https://github.com/LeSuisse/nixpkgs/commit/81b82a2934521dffef76f7ca305d8d4e22fe7262
- https://github.com/libarchive/libarchive/commit/eb7939b24a681a04648a59cdebd386b1e9dc9237.patch
- https://github.com/libarchive/libarchive/releases/tag/v3.7.4
- https://lists.fedoraproject.org/archives/list/[email protected]/message/EWANFZ6NEMXFCALXWI2AFKYBOLONAVFC/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/TWAMR5TY47UKVYMWQXB34CWSBNTRYMBV/
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26256
- https://www.openwall.com/lists/oss-security/2024/06/04/2
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-26256