CVE-2022-47112

EUVD-2022-49887
7-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later versions are unaffected.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.5 LOW
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 8.76%
Affected Products (NVD)
VendorProductVersion
7-zip7-zip
22.01
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
7zip
bookworm
unimportant
forky
unimportant
sid
unimportant
trixie
unimportant
p7zip
bookworm
unimportant
bullseye
unimportant
bullseye (security)
unimportant
trixie
16.02+transitional.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
7zip
focal
dne
jammy
needs-triage
noble
needs-triage
oracular
ignored
plucky
ignored
questing
ignored
resolute
needs-triage
p7zip
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
not-affected
oracular
not-affected
plucky
not-affected
questing
not-affected
resolute
dne
trusty
needs-triage
xenial
ignored