Описание
The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite two bytes at multiple offsets beyond the allocated buffer size: buffer+512*i-2, for i=9, i=10, i=11, etc.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | 24.09+dfsg-7 |
esm-apps/jammy | released | 21.07+dfsg-4ubuntu0.1~esm1 |
esm-apps/noble | released | 23.01+dfsg-11ubuntu0.1~esm1 |
esm-infra/focal | DNE | |
focal | DNE | |
jammy | needed | |
mantic | ignored | end of life, was needs-triage |
noble | needed | |
oracular | not-affected | 24.08+dfsg-1 |
plucky | not-affected | 24.09+dfsg-7 |
Показывать по
EPSS
8.4 High
CVSS3
Связанные уязвимости
The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite two bytes at multiple offsets beyond the allocated buffer size: buffer+512*i-2, for i=9, i=10, i=11, etc.
The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) conta ...
The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite two bytes at multiple offsets beyond the allocated buffer size: buffer+512*i-2, for i=9, i=10, i=11, etc.
Уязвимость обработчика NTFS в файле NtfsHandler.cpp архиватора 7-Zip, позволяющая нарушителю выполнить произвольный код
EPSS
8.4 High
CVSS3