Integer Underflow Vulnerability in 7-Zip Software by Ppm7d.c
CVE-2023-31102

7.8HIGH

Key Information:

Vendor

7-zip

Status
Vendor
CVE Published:
3 November 2023

What is CVE-2023-31102?

A critical vulnerability exists in 7-Zip, specifically in the Ppm7.c component prior to version 23.00. This vulnerability arises from an integer underflow, allowing for invalid read operations when processing specially crafted 7Z archives. If exploited, this could potentially allow attackers to manipulate memory and execute unintended actions, posing a significant threat to users relying on the software for file compression and decompression. Maintaining the latest version of 7-Zip is advised to mitigate this risk.

References

EPSS Score

38% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-31102 : Integer Underflow Vulnerability in 7-Zip Software by Ppm7d.c