CVE-2024-37407: Libarchive

Critical severity, CVSS 9.1. EPSS: 1% chance of exploitation in the next 30 days.

Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled. This occurs in slurp_central_directory in archive_read_support_format_zip.c.

Affected products

Published 2024-06-08. Last modified 2026-06-17.