Vulnerability Bulletins

DSA-4104 p7zip - security update

   
Affected software Debian
 
landave discovered a heap-based buffer overflow vulnerability in theNCompress::NShrink::CDecoder::CodeReal method in p7zip, a 7zr filearchiver with high compression ratio. A remote attacker can takeadvantage of this flaw to cause a denial-of-service or, potentially theexecution of arbitrary code with the privileges of the user runningp7zip, if a specially crafted shrinked ZIP archive is processed.

More info:

https://www.debian.org/security/2018/dsa-4104