Loading
Generated remediation guidance and an executive summary. No account required.
list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.
Use CWE-252, Libarchive vendor hub and Libarchive product page to widen CVE-2025-25724 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-5914, CVE-2024-48958 and CVE-2024-48957 for nearby disclosures in the same product family.