Memory Corruption Vulnerability in 7-Zip Software and p7zip Tool
CVE-2018-5996

7.8HIGH

Key Information:

Vendor
7-zip
Vendor
CVE Published:
31 January 2018

Summary

The vulnerability in 7-Zip and p7zip arises due to improper exception handling in the NCompress::NRar3::CDecoder::Code method. This flaw can result in multiple memory corruption issues specifically within the PPMd code, which may be exploited by remote attackers. Attackers can craft specially designed RAR archives to trigger a segmentation fault, potentially leading to a denial of service or even executing arbitrary code on affected systems.

References

EPSS Score

8% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.