First published: Mon Jan 05 2015(Updated: )
It was reported [1] that p7zip suffers from a directory traversal flaw. This could for the overwriting of arbitrary files through uncompressing a crafted archive, with the privileges of the user running 7z. For example: $ ln -s /tmp foo $ 7z a test.7z foo $ rm foo $ mkdir foo $ echo hello > foo/test $ 7z a test.7z foo/test $ rm -rf foo $ 7z x test.7z This will create 'foo' as a symlink to /tmp which will in turn contain the file 'test' with the privileges of the user unarchiving 'test.7z'. [1] <a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774660">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774660</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fedoraproject Fedora | =22 | |
Fedoraproject Fedora | =23 | |
Oracle Solaris | =10.0 | |
Oracle Solaris | =11.2 | |
7-zip P7zip | =9.20.1 | |
debian/p7zip | <=9.04~dfsg.1-1<=9.20.1~dfsg.1-4 | 9.20.1~dfsg.1-4.2 9.04~dfsg.1-1+deb6u1 9.20.1~dfsg.1-4.1+deb8u1 9.20.1~dfsg.1-4+deb7u1 |
debian/p7zip | 16.02+dfsg-8 16.02+transitional.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.