Heap Buffer Overflow in p7zip by 7-Zip
CVE-2022-47069

7.8HIGH

Key Information:

Vendor
7-zip
Status
Vendor
CVE Published:
22 August 2023

Summary

The p7zip software version 16.02 has been identified to have a heap buffer overflow vulnerability in the method NArchive::NZip::CInArchive::FindCd(bool), which can be exploited during the processing of zip files. This could potentially allow an attacker to execute arbitrary code or impact data integrity through crafted zip files, highlighting the importance of promptly updating the software to mitigate risks.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.