OESA-2021-1294
Dashboard / Vulnerabilities / OESA-2021-1294
OESA-2021-1294
Summary: p7zip security update
Details: 7za for Linux system to archive file as 7z file format Security Fix(es): Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to cause a denial of service (out-of-bounds write) or potentially execute arbitrary code via a crafted ZIP archive.(CVE-2017-17969) Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory corruptions within the PPMd code, allows remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.(CVE-2018-5996) Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.(CVE-2018-10115) A null pointer dereference bug affects the 16.02 and many old versions of p7zip. A lack of null pointer check for the variable folders.PackPositions in function CInArchive::ReadAndDecodePackedStreams in CPP/7zip/Archive/7z/7zIn.cpp, as used in the 7z.so library and in 7z applications, will cause a crash and a denial of service when decoding malformed 7z files.(CVE-2016-9296)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1294, https://nvd.nist.gov/vuln/detail/CVE-2017-17969, https://nvd.nist.gov/vuln/detail/CVE-2018-5996, https://nvd.nist.gov/vuln/detail/CVE-2018-10115, https://nvd.nist.gov/vuln/detail/CVE-2016-9296
Affected packages
Package
Name: p7zip
Purl: pkg:rpm/openEuler/p7zip&distro=openEuler-20.03-LTS-SP2
Affected ranges
Type: ECOSYSTEM
Events:
