Blog post: https://clearbluejar.github.io/posts/patch-tuesday-diffing-cve-2024-20696-windows-libarchive-rce/
A simple test harness for CVE-2024-20696
- Download a version of archiveint.dll that you want to test
- Update the path here
- Update the file path to point to the test archive to process. A sample one bsdtar-invalid-read.rar