Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-10115

Опубликовано: 02 мая 2018
Источник: debian
EPSS Низкий

Описание

Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
p7zip-rarfixed16.02-3package
p7zip-rarno-dsastretchpackage
p7zip-rarno-dsajessiepackage
p7zip-rarno-dsawheezypackage

Примечания

  • https://landave.io/2018/05/7-zip-from-uninitialized-memory-to-remote-code-execution/

  • https://sourceforge.net/p/sevenzip/discussion/45797/thread/adc65bfa/

EPSS

Процентиль: 92%
0.0758
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 8 лет назад

Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.

CVSS3: 9.8
redhat
почти 8 лет назад

Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.

CVSS3: 7.8
nvd
почти 8 лет назад

Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.

CVSS3: 7.8
github
больше 3 лет назад

Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.

EPSS

Процентиль: 92%
0.0758
Низкий