Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory corruptions within the PPMd code, allows remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| 7 Zip 7 Zip | 7-zip-7-zip-upgrade-latest | Jul 26, 2024 | Jan 31, 2018 | |
| Alpine Linux | alpine-linux-upgrade-p7zip | Aug 10, 2018 | Jan 31, 2018 | |
| Debian | debian-upgrade-p7zip-rar | Jul 30, 2024 | Jan 31, 2018 | |
| Freebsd | freebsd-upgrade-package-p7zip-codec-rar | Feb 11, 2018 | Feb 10, 2018 | |
| Oracle Solaris | oracle-solaris-11-3-upgrade-compress-p7zip-16-2-3-0-175-3-34-0-2-0 | Jul 18, 2018 | Jan 31, 2018 | |
| Suse | — | suse-upgrade-p7zip | Feb 20, 2018 | Jan 31, 2018 |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | Jan 31, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub