Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-52169

Опубликовано: 03 июл. 2024
Источник: debian
EPSS Низкий

Описание

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
7zipfixed24.05+dfsg-1package
7zipfixed22.01+dfsg-8+deb12u1bookwormpackage
p7zipfixed16.02+transitional.1package

Примечания

  • Crash in CLI tool, no security impact

  • https://sourceforge.net/p/sevenzip/bugs/2402/

  • https://dfir.ru/2024/06/19/vulnerabilities-in-7-zip-and-ntfs3/

  • https://www.openwall.com/lists/oss-security/2024/07/03/10

  • Since p7zip/16.02+transitional.1 src:p7zip is only a empty source package

  • depending on 7zip. Mark this version as fixed version.

EPSS

Процентиль: 65%
0.00502
Низкий

Связанные уязвимости

CVSS3: 8.2
ubuntu
12 месяцев назад

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.

CVSS3: 8.2
nvd
12 месяцев назад

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.

github
12 месяцев назад

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.

CVSS3: 8.2
fstec
почти 2 года назад

Уязвимость функции CFileNameAttr::Parse() файла NtfsHandler.cpp архиватора 7-Zip, позволяющая нарушителю загружать произвольные файлы и получить несанкционированный доступ к защищаемой информации

suse-cvrf
11 месяцев назад

Security update for p7zip

EPSS

Процентиль: 65%
0.00502
Низкий