Memory Corruption Vulnerability in 7-Zip Software and p7zip Tool
CVE-2018-5996
7.8HIGH
Summary
The vulnerability in 7-Zip and p7zip arises due to improper exception handling in the NCompress::NRar3::CDecoder::Code method. This flaw can result in multiple memory corruption issues specifically within the PPMd code, which may be exploited by remote attackers. Attackers can craft specially designed RAR archives to trigger a segmentation fault, potentially leading to a denial of service or even executing arbitrary code on affected systems.
References
EPSS Score
8% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved