PT-2018-9690 · 7 Zip+2 · 7-Zip+1

Publicado

2018-05-02

·

Atualizado

2021-07-31

·

CVE-2018-10115

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: 7-Zip versions 18.03 and earlier
Description: The issue is related to the incorrect initialization logic of RAR decoder objects, which can lead to the usage of uninitialized memory. This can allow remote attackers to cause a denial of service, resulting in a segmentation fault, or potentially execute arbitrary code via a crafted RAR archive.
Recommendations: For 7-Zip versions 18.03 and earlier, update to a version later than 18.03 to resolve the issue.

Exploit

Correção

DoS

Use of Uninitialized Resource

Improper Initialization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2591
CVE-2018-10115
OESA-2021-1294

Produtos afetados

7-Zip
Alt Linux