Memory Corruption Vulnerability in 7-Zip Software and p7zip Tool
CVE-2018-5996
7.8HIGH
What is CVE-2018-5996?
The vulnerability in 7-Zip and p7zip arises due to improper exception handling in the NCompress::NRar3::CDecoder::Code method. This flaw can result in multiple memory corruption issues specifically within the PPMd code, which may be exploited by remote attackers. Attackers can craft specially designed RAR archives to trigger a segmentation fault, potentially leading to a denial of service or even executing arbitrary code on affected systems.