Products
7-Zip
- before 24.01
Source
cve@mitre.org
Tags
CVE-2023-52169 details
Published : July 3, 2024, 6:15 p.m.
Last Modified : July 3, 2024, 7:15 p.m.
Last Modified : July 3, 2024, 7:15 p.m.
Description
The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.
CVSS Score
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|
References
URL | Source |
---|---|
http://www.openwall.com/lists/oss-security/2024/07/03/10 | cve@mitre.org |
https://sourceforge.net/p/sevenzip/bugs/2402/ | cve@mitre.org |
https://www.openwall.com/lists/oss-security/2024/07/03/10 | cve@mitre.org |
This website uses the NVD API, but is not approved or certified by it.