Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory corruptions within the PPMd code, allows remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| 7 Zip | — | — | May 16, 2018 | Jan 31, 2018 |
| 7 Zip 7 Zip | — | Upgrade 7-Zip to the latest version | Jul 26, 2024 | Jan 31, 2018 |
| Alpine Linux | — | Upgrade p7zip | Aug 10, 2018 | Jan 31, 2018 |
| Debian | — | Upgrade p7zip-rar | Jul 30, 2024 | Jan 31, 2018 |
| Freebsd | — | Upgrade p7zip-codec-rar | Feb 11, 2018 | Feb 10, 2018 |
| Oracle Solaris | — | Upgrade compress/p7zip to version 16.2.3-0.175.3.34.0.2.0 on Solaris 11.3 | Jul 18, 2018 | Jan 31, 2018 |
| Suse | — | Upgrade p7zip | Feb 20, 2018 | Jan 31, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jan 31, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub