Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-53816

Опубликовано: 17 июл. 2025
Источник: debian
EPSS Низкий

Описание

7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to memory corruption and denial of service in versions of 7-Zip prior to 25.0.0. Version 25.0.0 contains a fix for the issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
7zip-rarfixed25.00+ds-1package
p7zip-rarfixed16.02+transitional.1package
p7zip-rarno-dsabookwormpackage

Примечания

  • https://securitylab.github.com/advisories/GHSL-2025-058_7-Zip/

  • https://www.openwall.com/lists/oss-security/2025/07/18/1

  • Since p7zip-rar/16.02+transitional.1 src:p7zip-rar is only a empty source package

  • depending on 7zip-rar. Mark this version as fixed version.

EPSS

Процентиль: 14%
0.00047
Низкий

Связанные уязвимости

ubuntu
около 1 месяца назад

7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to memory corruption and denial of service in versions of 7-Zip prior to 25.0.0. Version 25.0.0 contains a fix for the issue.

nvd
около 1 месяца назад

7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to memory corruption and denial of service in versions of 7-Zip prior to 25.0.0. Version 25.0.0 contains a fix for the issue.

CVSS3: 6.2
fstec
4 месяца назад

Уязвимость метода NCompress::NRar5::CDecoder декодера RAR5 архиватора 7-Zip, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.2
redos
25 дней назад

Множественные уязвимости 7zip

EPSS

Процентиль: 14%
0.00047
Низкий