Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g8p4-4qgr-rf4f

Опубликовано: 03 июл. 2024
Источник: github
Github: Не прошло ревью

Описание

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.

EPSS

Процентиль: 65%
0.00502
Низкий

Связанные уязвимости

CVSS3: 8.2
ubuntu
12 месяцев назад

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.

CVSS3: 8.2
nvd
12 месяцев назад

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.

CVSS3: 8.2
debian
12 месяцев назад

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) conta ...

CVSS3: 8.2
fstec
почти 2 года назад

Уязвимость функции CFileNameAttr::Parse() файла NtfsHandler.cpp архиватора 7-Zip, позволяющая нарушителю загружать произвольные файлы и получить несанкционированный доступ к защищаемой информации

suse-cvrf
11 месяцев назад

Security update for p7zip

EPSS

Процентиль: 65%
0.00502
Низкий