Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-52169

Опубликовано: 03 июл. 2024
Источник: ubuntu
Приоритет: medium
CVSS3: 8.2

Описание

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.

РелизСтатусПримечание
devel

not-affected

24.09+dfsg-7
esm-apps/jammy

released

21.07+dfsg-4ubuntu0.1~esm1
esm-apps/noble

released

23.01+dfsg-11ubuntu0.1~esm1
esm-infra/focal

DNE

focal

DNE

jammy

needed

mantic

ignored

end of life, was needs-triage
noble

needed

oracular

not-affected

24.08+dfsg-1
plucky

not-affected

24.09+dfsg-7

Показывать по

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
nvd
12 месяцев назад

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.

CVSS3: 8.2
debian
12 месяцев назад

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) conta ...

github
12 месяцев назад

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.

CVSS3: 8.2
fstec
почти 2 года назад

Уязвимость функции CFileNameAttr::Parse() файла NtfsHandler.cpp архиватора 7-Zip, позволяющая нарушителю загружать произвольные файлы и получить несанкционированный доступ к защищаемой информации

suse-cvrf
11 месяцев назад

Security update for p7zip

8.2 High

CVSS3