Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-2334

Опубликовано: 13 дек. 2016
Источник: debian
EPSS Средний

Описание

Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HFS+ image.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
p7zipfixed15.14.1+dfsg-2package
p7zipnot-affectedjessiepackage
p7zipnot-affectedwheezypackage

Примечания

  • http://www.talosintel.com/reports/TALOS-2016-0093/

  • https://twitter.com/_Icewall/status/739731922998448129

EPSS

Процентиль: 95%
0.16299
Средний

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 9 лет назад

Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HFS+ image.

CVSS3: 7.8
nvd
около 9 лет назад

Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HFS+ image.

CVSS3: 7.8
github
больше 3 лет назад

Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HFS+ image.

EPSS

Процентиль: 95%
0.16299
Средний