Vulnerabilities (CVE-2023-40481, CVE-2023-31102) in 7-ZIP; fixed in version 23.00 (August 2023) (2024)

Posted on 2023-09-03 by guenni

Vulnerabilities (CVE-2023-40481, CVE-2023-31102) in 7-ZIP; fixed in version 23.00 (August 2023) (1)[German]A short update from the end of August 2023. Security researchers have found two vulnerabilities in the 7-Zip program, which is used to pack and unpack ZIP archive files. The vulnerabilities CVE-2023-40481 and CVE-2023-31102 are classified as high-risk from a security perspective. Attackers could possibly elevate privileges.

Advertising

Vulnerabilities (CVE-2023-40481, CVE-2023-31102) in 7-ZIP; fixed in version 23.00 (August 2023) (2)I had reported about a vulnerability in WinRAR in the blog post WinRAR Code Execution Vulnerability CVE-2023-40477 at the end of August. German blog reader Ralf had pointed out later, that vulnerabilities in the packing program 7-ZIP has became publicin the discussion area – and Stefan Kanthak also sent me a mail with hints (thanks for that). Two serious vulnerabilities were published by the Zero-Day-Initiative.

CVE-2023-31102

CVE-2023-31102 is a 7Z File Parsing Integer Underflow Remote Code Execution vulnerability in 7-Zip that has been assigned a CVE score of 7.8 (i.e., risk is high). The Zero Day Initiative writes that this vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability because the target must visit a malicious page or open a malicious file.

See Also
7z Format

The specific vulnerability exists is in the analysis of 7Z files. The problem results from the lack of proper validation of user-supplied data, which can lead to an integer underflow before writing to memory. An attacker can exploit this vulnerability to execute code in the context of the current process.

CVE-2023-40481

CVE-2023-40481 is a SquashFS File Parsing Out-Of-Bounds Write Remote Code Execution vulnerability in 7-Zip that has been assigned a CVE score of 7.8 (i.e., high risk). The vulnerability allows Romte attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is also required to exploit this vulnerability, as the target must visit a malicious page or open a malicious file.

The specific vulnerability arises during the analysis of SQFS files due to the lack of proper validation of user-supplied data. This can cause a write operation to exceed the end of an allocated buffer. An attacker can exploit this vulnerability to execute code in the context of the current process.

Advertising

Patch available

Both vulnerabilities were reported to the 7-ZIP developers on November 21, 2022 and were closed (according to Zero Day Initiative from August 23, 2023) with an update of the software to version 23.00 (at that time still beta). Thus, anyone using the program should update to the newest version. Currently version 23.01 is offered for download.

Cookies helps to fund this blog: Cookie settings
Advertising


This entry was posted in Security, Software, Update and tagged Security, Software, Update. Bookmark the permalink.

Vulnerabilities (CVE-2023-40481, CVE-2023-31102) in 7-ZIP; fixed in version 23.00 (August 2023) (2024)

FAQs

What is CVE-2023-31102 7-Zip? ›

What is CVE-2023-31102? CVE-2023-31102 is a high-severity vulnerability affecting the PPMD codec of the 7-Zip software, specifically in the Ppmd7. c file. This vulnerability is present in 7-Zip versions prior to 23.00 and can lead to an integer underflow and invalid read operation via a crafted 7Z archive.

What is the vulnerability of 7-Zip 23? ›

CVE-2023-31102 is a 7Z File Parsing Integer Underflow Remote Code Execution vulnerability in 7-Zip that has been assigned a CVE score of 7.8 (i.e., risk is high). The Zero Day Initiative writes that this vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip.

What is the security flaw in 7-Zip? ›

7-Zip vulnerability or CVE-2022-29072 is an active zero-day vulnerability and is characterized as allowing privilege escalation and command execution for Windows when a file with the . 7z extension is dragged to the Help > Contents area.

What is the CVE 2023 25136 vulnerability? ›

The CVE-2023-25136 vulnerability is not listed in CISA's Known Exploited Vulnerabilities Catalog. This double-free issue in OpenSSH server 9.1 has been fixed in version 9.2. Although exploiting the vulnerability is considered difficult, it's important to update your system to mitigate potential risks.

What is 7-Zip and is it safe? ›

7-zip is generally considered safe to use. It has been widely used for many years, and its source code has been reviewed by security experts due to its open-source nature. However, like any software, it's important to download it from trusted sources and keep it up to date to minimize any potential security risks.

Is 7-Zip encrypted? ›

7-Zip is a free file compression program that also allows you to encrypt and password protect the files you compress. You can compress multiple files into a single archive file. For someone to open an encrypted file created with 7-Zip that person will need to have 7-Zip or a compatible program.

What is the security issue of 7-Zip? ›

CVE-2023-52169

The NtfsHandler. cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image.

What is the weakest link of security? ›

The weakest link in any computer security system is people.

What are the disadvantages of ZIP? ›

The Disadvantages

They include file size limits, file type limits, corruption and mobility issues. One of many disadvantages associated with ZIP archive files is compression limits. Some files cannot be compressed much more than they already are. This is especially true for MP3 files and JPG files.

What is CVE 2023 38408? ›

CVE-2023-38408 is a vulnerability that enables remote code execution and resides in the SSH-agent's forwarded feature, particularly in relation to the PKCS#11 providers. Exploiting the SSH-agent's support for PKCS#11 under specific conditions allows attackers to execute remote code through a forwarded agent socket.

What is CVE 2023 28531? ›

ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints.

What is CVE 2023 21823? ›

CVE-2023-21823 is a critical security vulnerability that affects the graphics component of Microsoft Windows. It allows an attacker to execute arbitrary code in an elevated context. It affects various versions of Microsoft Windows, including Windows 10 and 11.

What is 7-Zip console vulnerability? ›

This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SQFS files.

What does 7-Zip error mean? ›

The 7-zip data error is an error message that appears when you try to extract or open a compressed file using the 7-Zip utility. This error typically occurs when the compressed file or archive has been corrupted or damaged in some way.

What is WinRAR vulnerability? ›

This vulnerability is exploited when WinRAR is used to extract a ZIP archive containing both a benign file and a folder sharing the same name as the benign file. When attempting to access the benign file, WinRAR inadvertently executes the file present within the folder.

What is Zip and 7-Zip? ›

Both . zip and . 7z are lossless compression formats. .7z is newer and is likely to give you a better compression ratio, but it's not as widely supported as . zip, and I think it's somewhat more computationally expensive to compress/decompress.

Top Articles
Rabbit Meat—Production, Consumption and Consumers’ Attitudes and Behavior
Do You Need a Real Estate License to Flip Houses?
Automated refuse, recycling for most residences; schedule announced | Lehigh Valley Press
Places 5 Hours Away From Me
Craigslist Benton Harbor Michigan
Samsung 9C8
Kris Carolla Obituary
Calamity Hallowed Ore
What's New on Hulu in October 2023
Sinai Web Scheduler
Aries Auhsd
State Of Illinois Comptroller Salary Database
Red Heeler Dog Breed Info, Pictures, Facts, Puppy Price & FAQs
iOS 18 Hadir, Tapi Mana Fitur AI Apple?
boohoo group plc Stock (BOO) - Quote London S.E.- MarketScreener
Yakimacraigslist
E22 Ultipro Desktop Version
The best TV and film to watch this week - A Very Royal Scandal to Tulsa King
Carson Municipal Code
Effingham Bookings Florence Sc
No Hard Feelings - Stream: Jetzt Film online anschauen
Strange World Showtimes Near Roxy Stadium 14
Costco Great Oaks Gas Price
Craigslist Appomattox Va
Gina Wilson All Things Algebra Unit 2 Homework 8
Tips and Walkthrough: Candy Crush Level 9795
Walgreens Bunce Rd
When Does Subway Open And Close
Obituaries Milwaukee Journal Sentinel
Fiona Shaw on Ireland: ‘It is one of the most successful countries in the world. It wasn’t when I left it’
Watson 853 White Oval
Receptionist Position Near Me
Wolfwalkers 123Movies
Uncovering the Enigmatic Trish Stratus: From Net Worth to Personal Life
Japanese Emoticons Stars
Emuaid Max First Aid Ointment 2 Ounce Fake Review Analysis
Craigslist Boerne Tx
Courtney Roberson Rob Dyrdek
Chadrad Swap Shop
2487872771
What Time Is First Light Tomorrow Morning
Arcadia Lesson Plan | Day 4: Crossword Puzzle | GradeSaver
Enjoy4Fun Uno
SF bay area cars & trucks "chevrolet 50" - craigslist
Sdn Fertitta 2024
3 Zodiac Signs Whose Wishes Come True After The Pisces Moon On September 16
Lyons Hr Prism Login
The Jazz Scene: Queen Clarinet: Interview with Doreen Ketchens – International Clarinet Association
The Quiet Girl Showtimes Near Landmark Plaza Frontenac
Game Akin To Bingo Nyt
Craigslist Cars And Trucks For Sale By Owner Indianapolis
Latest Posts
Article information

Author: Catherine Tremblay

Last Updated:

Views: 5751

Rating: 4.7 / 5 (67 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Catherine Tremblay

Birthday: 1999-09-23

Address: Suite 461 73643 Sherril Loaf, Dickinsonland, AZ 47941-2379

Phone: +2678139151039

Job: International Administration Supervisor

Hobby: Dowsing, Snowboarding, Rowing, Beekeeping, Calligraphy, Shooting, Air sports

Introduction: My name is Catherine Tremblay, I am a precious, perfect, tasty, enthusiastic, inexpensive, vast, kind person who loves writing and wants to share my knowledge and understanding with you.