A null pointer dereference bug affects the 16.02 and many old versions of p7zip. A lack of null pointer check for the variable folders.PackPositions in function CInArchive::ReadAndDecodePackedStreams in CPP/7zip/Archive/7z/7zIn.cpp, as used in the 7z.so library and in 7z applications, will cause a crash and a denial of service when decoding malformed 7z files.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| 7 Zip | — | — | May 16, 2018 | Nov 11, 2016 |
| Alpine Linux | — | Upgrade p7zip | Sep 20, 2017 | Nov 12, 2016 |
| Debian | — | Upgrade p7zip | Jul 30, 2024 | Nov 12, 2016 |
| Freebsd | — | Upgrade p7zip | Dec 10, 2025 | Nov 30, 2016 |
| Oracle Solaris | — | Upgrade compress/p7zip to version 16.2.1-0.175.3.29.0.1.0 on Solaris 11.3 | Feb 22, 2018 | Nov 11, 2016 |
| Suse | — | Upgrade p7zip | May 20, 2018 | Nov 11, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub