Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| 7 Zip | — | — | May 16, 2018 | May 13, 2018 |
| 7 Zip 7 Zip | — | Upgrade 7-Zip to the latest version | Jul 26, 2024 | May 2, 2018 |
| Alpine Linux | — | Upgrade p7zip | Mar 26, 2024 | May 2, 2018 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 2, 2018 |
| Debian | — | Upgrade p7zip-rar | Jul 30, 2024 | May 2, 2018 |
| Freebsd | — | Upgrade p7zip | Nov 4, 2022 | Dec 11, 2021 |
| Oracle Solaris | — | Upgrade compress/p7zip to version 16.2.3-0.175.3.34.0.2.0 on Solaris 11.3 | Jul 18, 2018 | May 2, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub