7.2 High
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:L/Au:N/C:C/I:C/A:C
7.8 High
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.4 High
AI Score
Confidence
High
0.001 Low
EPSS
Percentile
23.8%
libarchive Remote Code Execution Vulnerability
CPE | Name | Operator | Version |
---|---|---|---|
nixpkgs | eq | 3.5.2 | |
nixpkgs | eq | 3.1.2 | |
libarchive | eq | 3.7.0-r0 | |
nixpkgs | eq | 3.5.1 | |
nixpkgs | eq | last-glibc-2.13 | |
nixpkgs | eq | 2.8.4 | |
nixpkgs | eq | 15.09-beta | |
libarchive | eq | 3.0.4-r0 | |
nixpkgs | eq | 192 | |
libarchive | eq | 3.3.2-r1 |
www.openwall.com/lists/oss-security/2024/06/04/2
www.openwall.com/lists/oss-security/2024/06/05/1
github.com/LeSuisse/nixpkgs/commit/81b82a2934521dffef76f7ca305d8d4e22fe7262
github.com/libarchive/libarchive/commit/eb7939b24a681a04648a59cdebd386b1e9dc9237.patch
github.com/libarchive/libarchive/releases/tag/v3.7.4
lists.fedoraproject.org/archives/list/[email protected]/message/EWANFZ6NEMXFCALXWI2AFKYBOLONAVFC/
lists.fedoraproject.org/archives/list/[email protected]/message/TWAMR5TY47UKVYMWQXB34CWSBNTRYMBV/
msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26256
www.openwall.com/lists/oss-security/2024/06/04/2
7.2 High
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:L/Au:N/C:C/I:C/A:C
7.8 High
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.4 High
AI Score
Confidence
High
0.001 Low
EPSS
Percentile
23.8%