First published: Wed Jan 31 2018(Updated: )
Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory corruptions within the PPMd code, allows remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/p7zip-rar | 16.02-3 | |
7-Zip 7-Zip | <18.00 | |
7-zip P7zip | <18.0 | |
Debian Debian Linux | =7.0 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5996 is a vulnerability in 7-Zip and p7zip that allows remote attackers to cause a denial of service or execute arbitrary code via a crafted RAR archive, due to insufficient exception handling in the PPMd code.
CVE-2018-5996 has a severity rating of 7.8 (high).
CVE-2018-5996 affects 7-Zip versions prior to 18.00 and p7zip versions prior to 18.0, as well as the p7zip-rar package version 16.02-3.
Yes, CVE-2018-5996 can be fixed by updating 7-Zip to version 18.00 or newer, updating p7zip to version 18.0 or newer, or applying the remedy provided for the p7zip-rar package version 16.02-3.
More information about CVE-2018-5996 can be found at the following references: [http://www.securitytracker.com/id/1040831](http://www.securitytracker.com/id/1040831), [https://0patch.blogspot.si/2018/02/two-interesting-micropatches-for-7-zip.html](https://0patch.blogspot.si/2018/02/two-interesting-micropatches-for-7-zip.html), [https://landave.io/2018/01/7-zip-multiple-memory-corruptions-via-rar-and-zip/](https://landave.io/2018/01/7-zip-multiple-memory-corruptions-via-rar-and-zip/)