ALT-PU-2018-2784-1
Closed vulnerabilities
Modified: 2024-11-21
CVE-2016-9296
A null pointer dereference bug affects the 16.02 and many old versions of p7zip. A lack of null pointer check for the variable folders.PackPositions in function CInArchive::ReadAndDecodePackedStreams in CPP/7zip/Archive/7z/7zIn.cpp, as used in the 7z.so library and in 7z applications, will cause a crash and a denial of service when decoding malformed 7z files.
- 94294
- 94294
- https://github.com/yangke/7zip-null-pointer-dereference
- https://github.com/yangke/7zip-null-pointer-dereference
- https://sourceforge.net/p/p7zip/bugs/185/
- https://sourceforge.net/p/p7zip/bugs/185/
- https://sourceforge.net/p/p7zip/discussion/383043/thread/648d34db/
- https://sourceforge.net/p/p7zip/discussion/383043/thread/648d34db/
Modified: 2024-11-21
CVE-2017-17969
Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to cause a denial of service (out-of-bounds write) or potentially execute arbitrary code via a crafted ZIP archive.
- 1040831
- 1040831
- https://0patch.blogspot.si/2018/02/two-interesting-micropatches-for-7-zip.html
- https://0patch.blogspot.si/2018/02/two-interesting-micropatches-for-7-zip.html
- https://landave.io/2018/01/7-zip-multiple-memory-corruptions-via-rar-and-zip/
- https://landave.io/2018/01/7-zip-multiple-memory-corruptions-via-rar-and-zip/
- [debian-lts-announce] 20180202 [SECURITY] [DLA 1268-1] p7zip security update
- [debian-lts-announce] 20180202 [SECURITY] [DLA 1268-1] p7zip security update
- USN-3913-1
- USN-3913-1
- DSA-4104
- DSA-4104
Modified: 2024-11-21
CVE-2018-10115
Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.
- 104132
- 104132
- 1040832
- 1040832
- https://landave.io/2018/05/7-zip-from-uninitialized-memory-to-remote-code-execution/
- https://landave.io/2018/05/7-zip-from-uninitialized-memory-to-remote-code-execution/
- https://sourceforge.net/p/sevenzip/discussion/45797/thread/adc65bfa/
- https://sourceforge.net/p/sevenzip/discussion/45797/thread/adc65bfa/
Modified: 2024-11-21
CVE-2018-5996
Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory corruptions within the PPMd code, allows remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.
- 1040831
- 1040831
- https://0patch.blogspot.si/2018/02/two-interesting-micropatches-for-7-zip.html
- https://0patch.blogspot.si/2018/02/two-interesting-micropatches-for-7-zip.html
- https://landave.io/2018/01/7-zip-multiple-memory-corruptions-via-rar-and-zip/
- https://landave.io/2018/01/7-zip-multiple-memory-corruptions-via-rar-and-zip/