CVE-2017-17969

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
30/01/2018
Last modified:
10/01/2025

Description

Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to cause a denial of service (out-of-bounds write) or potentially execute arbitrary code via a crafted ZIP archive.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:7-zip:7-zip:*:*:*:*:*:*:*:* 18.00 (excluding)
cpe:2.3:a:7-zip:p7zip:*:*:*:*:*:*:*:* 18.0 (excluding)
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*