Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-47112

Опубликовано: 19 апр. 2025
Источник: debian

Описание

7-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later versions are unaffected.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
7zipunfixedpackage
p7zipfixed16.02+transitional.1package

Примечания

  • Since p7zip/16.02+transitional.1 src:p7zip is only a empty source package

  • depending on 7zip. Mark this version as fixed version.

  • https://github.com/boofish/semantic-bugs/

  • Negligible security impact

Связанные уязвимости

CVSS3: 2.5
ubuntu
10 месяцев назад

7-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later versions are unaffected.

CVSS3: 2.5
nvd
10 месяцев назад

7-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later versions are unaffected.

CVSS3: 2.5
github
10 месяцев назад

7-Zip through 24.09 does not report an error for certain invalid xz files, involving stream flags and reserved bits.

CVSS3: 2.5
fstec
10 месяцев назад

Уязвимость архиватора 7-Zip, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю оказать воздействие на целостность защищаемой информации