JLSEC-2025-250 Medium 4.0
libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_su...
libarchive through 3.7.7 has a heap-based buffer over-read in headergnulonglink in archivereadsupportformattar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.