Debian Security Update DSA-4104 p7zip - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,802
Reaction score
74
Credits
-1,257
'landave' discovered a heap-based buffer overflow vulnerability in the NCompress::NShrink::CDecoder::CodeReal method in p7zip, a 7zr file archiver with high compression ratio. A remote attacker can take advantage of this flaw to cause a denial-of-service or, potentially the execution of arbitrary code with the privileges of the user running p7zip, if a specially crafted shrinked ZIP archive is processed.

Continue reading...
 


Follow Linux.org

Members online


Latest posts

Top