PT-2023-9823 · Igor Pavlov+6 · 7-Zip+6

Maxim Suhanov

·

Published

2023-08-18

·

Updated

2025-07-11

·

CVE-2023-52169

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions 7-Zip versions prior to 24.01
Description The issue is related to an out-of-bounds read in the NTFS handler of 7-Zip. This allows an attacker to read beyond the intended buffer, with the bytes read presented as part of a filename in the file system image. The security relevance of this issue is notable in web-service use cases where untrusted users can upload files that are then extracted by a server-side 7-Zip process. The vulnerability can be exploited by a remote attacker to upload arbitrary files and gain unauthorized access to protected information.
Recommendations For versions prior to 24.01, update to version 24.01 or later to resolve the issue. As a temporary workaround, consider restricting the use of the NTFS handler in 7-Zip to minimize the risk of exploitation. Avoid using 7-Zip to extract files from untrusted sources until the issue is resolved.

Fix

Out of bounds Read

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2024-15154
ALT-PU-2024-15240
BDU:2024-04975
BDU:2024-11604
CVE-2023-52169
OESA-2025-1748
OPENSUSE-SU-2024_2625-1
SUSE-SU-2024:2475-1
SUSE-SU-2024:2625-1
USN-7438-1

Affected Products

7-Zip
Alt Linux
Debian
Linuxmint
Red Os
Suse
Ubuntu