ALT-PU-2024-3664-1
Package p7zip updated to version 17.05-alt2 for branch sisyphus_e2k.
Closed vulnerabilities
Published: 2016-11-12
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2016-9296
A null pointer dereference bug affects the 16.02 and many old versions of p7zip. A lack of null pointer check for the variable folders.PackPositions in function CInArchive::ReadAndDecodePackedStreams in CPP/7zip/Archive/7z/7zIn.cpp, as used in the 7z.so library and in 7z applications, will cause a crash and a denial of service when decoding malformed 7z files.
Severity: HIGH (7.5)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
- 94294
- 94294
- https://github.com/yangke/7zip-null-pointer-dereference
- https://github.com/yangke/7zip-null-pointer-dereference
- https://sourceforge.net/p/p7zip/bugs/185/
- https://sourceforge.net/p/p7zip/bugs/185/
- https://sourceforge.net/p/p7zip/discussion/383043/thread/648d34db/
- https://sourceforge.net/p/p7zip/discussion/383043/thread/648d34db/
Published: 2023-08-22
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2022-47069
p7zip 16.02 was discovered to contain a heap-buffer-overflow vulnerability via the function NArchive::NZip::CInArchive::FindCd(bool) at CPP/7zip/Archive/Zip/ZipIn.cpp.
Severity: HIGH (7.8)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
Closed bugs
При распаковке zip архива сообщает об уже существующем файле