Impact
A strcpy heap-based buffer overflow exists in libarchive’s gzip writer, triggered by the original‑filename field used in archive_compressor_gzip_open. The overflow can corrupt the heap, potentially leading to a memory corruption. The flaw exists.x before 3.8.2 and directly relates to bsdtar. The vulnerability is confined to processes that load the affected library and invoke the gzip compression path, so impact is local but can is identified as CWE-120 and CWE-122.
Affected Systems
The libc archive component, libarchive, version 3.8.x prior to 3.8.2 is affected. Users of this library, including applications that wrap or use libarchive for gzip archive creation (for example bsdtar), should verify the version and consider upgrading.
Risk and Exploitability
The vulnerability carries a CVSS score of 2.5, indicating low overall severity, and has an EPSS score of < 1%, indicating a marginally plausible exploitation scenario. It is not listed in CISA’s KEV catalog. The likely attack vector involves an attacker supplying a crafted original‑filename field to a process that uses libarchive’s gzip writer. Because the original‑filename is not derived from other input data, the scenario requires the attacker to control the filename supplied by the application or the environment. Low CVSS and limited exploitation probability mitigate immediate risk; nevertheless, the presence of a heap‑based overwrite warrants remediation.
OpenCVE Enrichment