PT-2016-7728 · 7 Zip+1 · P7Zip+1

Ramesh Uppuluri

·

Publicado

2016-11-12

·

Atualizado

2024-06-15

·

CVE-2016-9296

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions p7zip versions 16.02 and earlier
Description A null pointer dereference bug affects the software, causing a crash and a denial of service when decoding malformed 7z files. This issue is due to a lack of null pointer check for the variable folders.PackPositions in the function CInArchive::ReadAndDecodePackedStreams in the 7z.so library and in 7z applications.
Recommendations For p7zip version 16.02 and earlier, consider updating to a newer version that includes a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2591
ALT-PU-2020-2373
ALT-PU-2021-3103
AZL-35091
AZL-6782
CVE-2016-9296
OESA-2021-1294
OPENSUSE-SU-2024:10322-1

Produtos afetados

Alt Linux
P7Zip