ALT-PU-2024-3664-1
Package p7zip updated to version 17.05-alt2 for branch sisyphus_e2k.
Closed vulnerabilities
Modified: 2025-04-12
CVE-2016-9296
A null pointer dereference bug affects the 16.02 and many old versions of p7zip. A lack of null pointer check for the variable folders.PackPositions in function CInArchive::ReadAndDecodePackedStreams in CPP/7zip/Archive/7z/7zIn.cpp, as used in the 7z.so library and in 7z applications, will cause a crash and a denial of service when decoding malformed 7z files.
- http://www.securityfocus.com/bid/94294
- https://github.com/yangke/7zip-null-pointer-dereference
- https://sourceforge.net/p/p7zip/bugs/185/
- https://sourceforge.net/p/p7zip/discussion/383043/thread/648d34db/
- http://www.securityfocus.com/bid/94294
- https://github.com/yangke/7zip-null-pointer-dereference
- https://sourceforge.net/p/p7zip/bugs/185/
- https://sourceforge.net/p/p7zip/discussion/383043/thread/648d34db/
Modified: 2025-11-20
CVE-2022-47069
p7zip 16.02 was discovered to contain a heap-buffer-overflow vulnerability via the function NArchive::NZip::CInArchive::FindCd(bool) at CPP/7zip/Archive/Zip/ZipIn.cpp. NOTE: the Supplier has found that this is not a buffer overflow; at most an out-of-bounds read can occur.
Closed bugs
При распаковке zip архива сообщает об уже существующем файле