CVE-2017-17969: Buffer Overflow
Published Jan 24, 2018
·Updated
Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to cause a denial of service (out-of-bounds write) or potentially execute arbitrary code via a crafted ZIP archive.
Affected Software
7 affected componentsFixes available
debian/p7zip<=9.20.1~dfsg.1-4.1, <=16.02+dfsg-4
16.02+dfsg-516.02+dfsg-3+deb9u19.20.1~dfsg.1-4.1+deb8u3
debian/p7zip
16.02+dfsg-816.02+transitional.1
7-Zip 7-Zip<18.00
7-Zip p7zip<18.0
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Event History
Jan 30, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·04:42 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·04:43 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2017-17969.
2
What is the severity of CVE-2017-17969?
The severity of CVE-2017-17969 is high with a score of 7.8.
3
What is the affected software?
The affected software is 7-Zip before version 18.00 and p7zip.
4
How can a remote attacker exploit CVE-2017-17969?
A remote attacker can exploit CVE-2017-17969 by sending a crafted ZIP archive, potentially causing a denial of service or executing arbitrary code.
5
Where can I find more information about CVE-2017-17969?
You can find more information about CVE-2017-17969 at the following references: [link1], [link2], [link3].