CVE-2016-2335: Buffer Overflow
Last updated 25 August 2025
Other sources
The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to cause a denial of service (out-of-bounds read) or execute arbitrary code via the PartitionRef field in the Long Allocation Descriptor in a UDF file.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-2335?
CVE-2016-2335 is a vulnerability in 7zip that allows remote attackers to cause a denial of service or execute arbitrary code via a UDF file.
What is the severity of CVE-2016-2335?
The severity of CVE-2016-2335 is high (8.8).
What software versions are affected by CVE-2016-2335?
The affected software versions are: 7zip 9.20, 15.05 beta, and p7zip 16.02+dfsg-6, 16.02+dfsg-8, 9.20.1~dfsg.1-4+, 15.14.1+dfsg-2, 9.20.1~dfsg.1-4.2ubuntu0.1, 13.2, 8.0, and 9.0.
How can I fix CVE-2016-2335?
To fix CVE-2016-2335, update to the patched versions of the affected software: 7zip 16.02+dfsg-6 or higher, 15.05 beta or higher, and p7zip 16.02+dfsg-6 or higher.
Where can I find more information about CVE-2016-2335?
More information about CVE-2016-2335 can be found at the following references: http://www.talosintel.com/reports/TALOS-2016-0094/, http://lists.opensuse.org/opensuse-updates/2016-06/msg00004.html, and http://www.debian.org/security/2016/dsa-3599.