Vulnerabilities (CVE-2023-40481, CVE-2023-31102) in 7-ZIP; fixed in version 23.00 (August 2023) (2024)

Posted on 2023-09-03 by guenni

Vulnerabilities (CVE-2023-40481, CVE-2023-31102) in 7-ZIP; fixed in version 23.00 (August 2023) (1)[German]A short update from the end of August 2023. Security researchers have found two vulnerabilities in the 7-Zip program, which is used to pack and unpack ZIP archive files. The vulnerabilities CVE-2023-40481 and CVE-2023-31102 are classified as high-risk from a security perspective. Attackers could possibly elevate privileges.

Advertising

Vulnerabilities (CVE-2023-40481, CVE-2023-31102) in 7-ZIP; fixed in version 23.00 (August 2023) (2)I had reported about a vulnerability in WinRAR in the blog post WinRAR Code Execution Vulnerability CVE-2023-40477 at the end of August. German blog reader Ralf had pointed out later, that vulnerabilities in the packing program 7-ZIP has became publicin the discussion area – and Stefan Kanthak also sent me a mail with hints (thanks for that). Two serious vulnerabilities were published by the Zero-Day-Initiative.

CVE-2023-31102

CVE-2023-31102 is a 7Z File Parsing Integer Underflow Remote Code Execution vulnerability in 7-Zip that has been assigned a CVE score of 7.8 (i.e., risk is high). The Zero Day Initiative writes that this vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability because the target must visit a malicious page or open a malicious file.

See Also
7z Format

The specific vulnerability exists is in the analysis of 7Z files. The problem results from the lack of proper validation of user-supplied data, which can lead to an integer underflow before writing to memory. An attacker can exploit this vulnerability to execute code in the context of the current process.

CVE-2023-40481

CVE-2023-40481 is a SquashFS File Parsing Out-Of-Bounds Write Remote Code Execution vulnerability in 7-Zip that has been assigned a CVE score of 7.8 (i.e., high risk). The vulnerability allows Romte attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is also required to exploit this vulnerability, as the target must visit a malicious page or open a malicious file.

The specific vulnerability arises during the analysis of SQFS files due to the lack of proper validation of user-supplied data. This can cause a write operation to exceed the end of an allocated buffer. An attacker can exploit this vulnerability to execute code in the context of the current process.

Advertising

Patch available

Both vulnerabilities were reported to the 7-ZIP developers on November 21, 2022 and were closed (according to Zero Day Initiative from August 23, 2023) with an update of the software to version 23.00 (at that time still beta). Thus, anyone using the program should update to the newest version. Currently version 23.01 is offered for download.

Cookies helps to fund this blog: Cookie settings
Advertising


This entry was posted in Security, Software, Update and tagged Security, Software, Update. Bookmark the permalink.

Vulnerabilities (CVE-2023-40481, CVE-2023-31102) in 7-ZIP; fixed in version 23.00 (August 2023) (2024)

FAQs

What is CVE-2023-31102 7-Zip? ›

What is CVE-2023-31102? CVE-2023-31102 is a high-severity vulnerability affecting the PPMD codec of the 7-Zip software, specifically in the Ppmd7. c file. This vulnerability is present in 7-Zip versions prior to 23.00 and can lead to an integer underflow and invalid read operation via a crafted 7Z archive.

What is the vulnerability of 7-Zip 23? ›

CVE-2023-31102 is a 7Z File Parsing Integer Underflow Remote Code Execution vulnerability in 7-Zip that has been assigned a CVE score of 7.8 (i.e., risk is high). The Zero Day Initiative writes that this vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip.

What is the security flaw in 7-Zip? ›

7-Zip vulnerability or CVE-2022-29072 is an active zero-day vulnerability and is characterized as allowing privilege escalation and command execution for Windows when a file with the . 7z extension is dragged to the Help > Contents area.

What is the CVE 2023 25136 vulnerability? ›

The CVE-2023-25136 vulnerability is not listed in CISA's Known Exploited Vulnerabilities Catalog. This double-free issue in OpenSSH server 9.1 has been fixed in version 9.2. Although exploiting the vulnerability is considered difficult, it's important to update your system to mitigate potential risks.

What is 7-Zip and is it safe? ›

7-zip is generally considered safe to use. It has been widely used for many years, and its source code has been reviewed by security experts due to its open-source nature. However, like any software, it's important to download it from trusted sources and keep it up to date to minimize any potential security risks.

Is 7-Zip encrypted? ›

7-Zip is a free file compression program that also allows you to encrypt and password protect the files you compress. You can compress multiple files into a single archive file. For someone to open an encrypted file created with 7-Zip that person will need to have 7-Zip or a compatible program.

What is the security issue of 7-Zip? ›

CVE-2023-52169

The NtfsHandler. cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image.

What is the weakest link of security? ›

The weakest link in any computer security system is people.

What are the disadvantages of ZIP? ›

The Disadvantages

They include file size limits, file type limits, corruption and mobility issues. One of many disadvantages associated with ZIP archive files is compression limits. Some files cannot be compressed much more than they already are. This is especially true for MP3 files and JPG files.

What is CVE 2023 38408? ›

CVE-2023-38408 is a vulnerability that enables remote code execution and resides in the SSH-agent's forwarded feature, particularly in relation to the PKCS#11 providers. Exploiting the SSH-agent's support for PKCS#11 under specific conditions allows attackers to execute remote code through a forwarded agent socket.

What is CVE 2023 28531? ›

ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints.

What is CVE 2023 21823? ›

CVE-2023-21823 is a critical security vulnerability that affects the graphics component of Microsoft Windows. It allows an attacker to execute arbitrary code in an elevated context. It affects various versions of Microsoft Windows, including Windows 10 and 11.

What is 7-Zip console vulnerability? ›

This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SQFS files.

What does 7-Zip error mean? ›

The 7-zip data error is an error message that appears when you try to extract or open a compressed file using the 7-Zip utility. This error typically occurs when the compressed file or archive has been corrupted or damaged in some way.

What is WinRAR vulnerability? ›

This vulnerability is exploited when WinRAR is used to extract a ZIP archive containing both a benign file and a folder sharing the same name as the benign file. When attempting to access the benign file, WinRAR inadvertently executes the file present within the folder.

What is Zip and 7-Zip? ›

Both . zip and . 7z are lossless compression formats. .7z is newer and is likely to give you a better compression ratio, but it's not as widely supported as . zip, and I think it's somewhat more computationally expensive to compress/decompress.

Top Articles
How to Answer "Where Do You See Yourself in 5 Years?" During an Interview
How Does The Luck Factor Work in Cardano Staking Mechanism?
Diario Las Americas Rentas Hialeah
Ups Stores Near
Tmf Saul's Investing Discussions
Euro (EUR), aktuální kurzy měn
Quick Pickling 101
Nyu Paralegal Program
Toyota Campers For Sale Craigslist
U.S. Nuclear Weapons Complex: Y-12 and Oak Ridge National Laboratory…
Taylor Swift Seating Chart Nashville
Keniakoop
Mens Standard 7 Inch Printed Chappy Swim Trunks, Sardines Peachy
Hair Love Salon Bradley Beach
Truth Of God Schedule 2023
Clear Fork Progress Book
Georgia Vehicle Registration Fees Calculator
Spider-Man: Across The Spider-Verse Showtimes Near Marcus Bay Park Cinema
Royal Cuts Kentlands
Ruse For Crashing Family Reunions Crossword
Doublelist Paducah Ky
[PDF] NAVY RESERVE PERSONNEL MANUAL - Free Download PDF
Who is Jenny Popach? Everything to Know About The Girl Who Allegedly Broke Into the Hype House With Her Mom
Www.craigslist.com Austin Tx
Sandals Travel Agent Login
1 Filmy4Wap In
What Individuals Need to Know When Raising Money for a Charitable Cause
Craigslist Ludington Michigan
Wolfwalkers 123Movies
Delta Math Login With Google
Guinness World Record For Longest Imessage
Tokioof
Jt Closeout World Rushville Indiana
Jeep Cherokee For Sale By Owner Craigslist
Eaccess Kankakee
Domino's Delivery Pizza
October 31St Weather
Encompass.myisolved
2023 Nickstory
Dcilottery Login
Parent Portal Pat Med
Az Unblocked Games: Complete with ease | airSlate SignNow
3500 Orchard Place
How to Connect Jabra Earbuds to an iPhone | Decortweaks
Minterns German Shepherds
Verizon Forum Gac Family
Automatic Vehicle Accident Detection and Messageing System – IJERT
Smoke From Street Outlaws Net Worth
Sam's Club Fountain Valley Gas Prices
Inside the Bestselling Medical Mystery 'Hidden Valley Road'
Saw X (2023) | Film, Trailer, Kritik
Latest Posts
Article information

Author: Catherine Tremblay

Last Updated:

Views: 5751

Rating: 4.7 / 5 (67 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Catherine Tremblay

Birthday: 1999-09-23

Address: Suite 461 73643 Sherril Loaf, Dickinsonland, AZ 47941-2379

Phone: +2678139151039

Job: International Administration Supervisor

Hobby: Dowsing, Snowboarding, Rowing, Beekeeping, Calligraphy, Shooting, Air sports

Introduction: My name is Catherine Tremblay, I am a precious, perfect, tasty, enthusiastic, inexpensive, vast, kind person who loves writing and wants to share my knowledge and understanding with you.