CVE-2020-21674: Libarchive
Medium severity, CVSS 6.5. EPSS: 2.1% chance of exploitation in the next 30 days.
Heap-based buffer overflow in archive_string_append_from_wcs() (archive_string.c) in libarchive-3.4.1dev allows remote attackers to cause a denial of service (out-of-bounds write in heap memory resulting into a crash) via a crafted archive file. NOTE: this only affects users who downloaded the development code from GitHub. Users of the product's official releases are unaffected.
Affected products
- Libarchive Libarchive: version 3.4.1 only
Published 2020-10-15. Last modified 2026-06-17.