Описание
Security update for python-py7zr
This update for python-py7zr fixes the following issues:
Changes in python-py7zr:
- CVE-2026-23879: crafted malicious symbolic link chains in an archive can lead to an arbitrary file write (bsc#1268669)
- CVE-2026-55195: unchecked extraction size can cause a denial of service (bsc#1268665)
- CVE-2026-55206: crafted .7z archive with a large numstreams value can cause a denial of service (bsc#1268666)
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1268665
- SUSE Bug 1268666
- SUSE Bug 1268669
- SUSE CVE CVE-2026-23879 page
- SUSE CVE CVE-2026-55195 page
- SUSE CVE CVE-2026-55206 page
Описание
py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below contain an an arbitrary file write vulnerability, which allows symbolic links to be recreated outside the destination directory via crafted malicious symbolic link chains. When using extractall to extract an archive, the library restores these symbolic links, linking them to arbitrary directories on the host file system. During extraction, the program only checks the link arcname within the destination directory, but ignores the combined symlink path resolution. Attackers can exploit this vulnerability by constructing malicious archives, thereby bypassing the directory boundary restrictions implemented by the extractor. Subsequent extraction of regular files through these symbolic links can result in arbitrary file writes. This vulnerability may lead to remote code execution, privilege escalation, data corruption, or denial of service. This issue has been fixed in version 1.1.3.
Затронутые продукты
Ссылки
- CVE-2026-23879
- SUSE Bug 1268669
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-55195
- SUSE Bug 1268665
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-55206
- SUSE Bug 1268666