CVE-2017-17969
30.01.2018, 16:29
Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to cause a denial of service (out-of-bounds write) or potentially execute arbitrary code via a crafted ZIP archive.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| 7-zip | 7-zip | 𝑥 < 18.00 |
| 7-zip | p7zip | 𝑥 < 18.0 |
| debian | debian_linux | 7.0 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| p7zip |
| ||||||||||||||||||
| p7zip-full |
|
Common Weakness Enumeration
References