CVE-2025-64031 - Low Severity Vulnerability
Vulnerable Library - libarchivev3.8.5
Multi-format archive and compression library
Library home page: https://github.com/libarchive/libarchive.git
Found in base branch: stable/4.0
Vulnerable Source Files (1)
/contrib/libarchive/libarchive/archive_write_add_filter_gzip.c
Vulnerability Details
libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9. This relates to bsdtar. Exploitation envisions a marginally plausible scenario in which original-filename is obtained from an untrusted party. (original-filename is not derived from the input data.)
Publish Date: 2026-09-14
URL: CVE-2025-64031
CVSS 3 Score Details (2.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: High
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-09-14
Fix Resolution: libarchive - 3.8.7,libarchive - 3.8.2,https://github.com/libarchive/libarchive.git - v3.8.2
Step up your Open Source Security Game with Mend here
CVE-2025-64031 - Low Severity Vulnerability
Multi-format archive and compression library
Library home page: https://github.com/libarchive/libarchive.git
Found in base branch: stable/4.0
libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9. This relates to bsdtar. Exploitation envisions a marginally plausible scenario in which original-filename is obtained from an untrusted party. (original-filename is not derived from the input data.)
Publish Date: 2026-09-14
URL: CVE-2025-64031
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: High
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.Type: Upgrade version
Release Date: 2026-09-14
Fix Resolution: libarchive - 3.8.7,libarchive - 3.8.2,https://github.com/libarchive/libarchive.git - v3.8.2
Step up your Open Source Security Game with Mend here