First published: Tue Jun 07 2016(Updated: )
Last updated 24 July 2024
Credit: cret@cert.org cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE openSUSE | =13.2 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
7-Zip 7-Zip | =9.20 | |
7-Zip 7-Zip | =15.05-beta | |
debian/p7zip | 16.02+dfsg-8 16.02+transitional.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2335 is a vulnerability in 7zip that allows remote attackers to cause a denial of service or execute arbitrary code via a UDF file.
The severity of CVE-2016-2335 is high (8.8).
The affected software versions are: 7zip 9.20, 15.05 beta, and p7zip 16.02+dfsg-6, 16.02+dfsg-8, 9.20.1~dfsg.1-4+, 15.14.1+dfsg-2, 9.20.1~dfsg.1-4.2ubuntu0.1, 13.2, 8.0, and 9.0.
To fix CVE-2016-2335, update to the patched versions of the affected software: 7zip 16.02+dfsg-6 or higher, 15.05 beta or higher, and p7zip 16.02+dfsg-6 or higher.
More information about CVE-2016-2335 can be found at the following references: http://www.talosintel.com/reports/TALOS-2016-0094/, http://lists.opensuse.org/opensuse-updates/2016-06/msg00004.html, and http://www.debian.org/security/2016/dsa-3599.