Описание
Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| 7zip | fixed | 23.01+dfsg-1 | package | |
| 7zip | no-dsa | bookworm | package | |
| p7zip | fixed | 16.02+transitional.1 | package |
Примечания
https://www.zerodayinitiative.com/advisories/ZDI-23-1165/
https://sourceforge.net/p/sevenzip/discussion/45797/thread/713c8a8269/
https://ds-security.com/post/integer-overflow-in-7-zip-cve-2023-31102/
Since p7zip/16.02+transitional.1 src:p7zip is only a empty source package
depending on 7zip. Mark this version as fixed version.
EPSS
Связанные уязвимости
Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.
Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.
7-Zip through 22.01 on Linux allows an integer underflow and code execution via a crafted 7Z archive.
Уязвимость компонента анализатора 7z-файлов архиватора 7-Zip, позволяющая нарушителю выполнить произвольный код
EPSS