7-Zip SquashFS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
CVE-2023-40481
7.8HIGH
What is CVE-2023-40481?
A vulnerability exists in 7-Zip related to the parsing of SquashFS (SQFS) files, which allows remote attackers to execute arbitrary code on installations of the software. This flaw arises from inadequate validation of user-supplied data when handling SQFS files, leading to out-of-bounds writes that can manipulate the memory buffer. Successful exploitation necessitates that a victim either visits a malicious website or opens a specifically crafted file, potentially allowing the attacker to execute code within the context of the affected application. For further details, see the advisories from the Zero Day Initiative and vendor discussions.
Affected Version(s)
7-Zip 22.01