Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2025-5916

Published: June 10, 2025Last modified: July 22, 2025

Description

A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive.

Severity score breakdown

ParameterValue
Base score5.6
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibarchiveFixed (3.8.0-r0)
StreamlibarchiveFixed (3.8.0-r0)

References

ON THIS PAGE