CVE-2018-5996: Buffer Overflow
Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory corruptions within the PPMd code, allows remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/p7zip-rarto a version that resolves this vulnerability.Fixed in 16.02-3
Event History
Frequently Asked Questions
What is CVE-2018-5996?
CVE-2018-5996 is a vulnerability in 7-Zip and p7zip that allows remote attackers to cause a denial of service or execute arbitrary code via a crafted RAR archive, due to insufficient exception handling in the PPMd code.
What is the severity of CVE-2018-5996?
CVE-2018-5996 has a severity rating of 7.8 (high).
How does CVE-2018-5996 affect the affected software?
CVE-2018-5996 affects 7-Zip versions prior to 18.00 and p7zip versions prior to 18.0, as well as the p7zip-rar package version 16.02-3.
Can CVE-2018-5996 be fixed?
Yes, CVE-2018-5996 can be fixed by updating 7-Zip to version 18.00 or newer, updating p7zip to version 18.0 or newer, or applying the remedy provided for the p7zip-rar package version 16.02-3.
Where can I find more information about CVE-2018-5996?
More information about CVE-2018-5996 can be found at the following references: [http://www.securitytracker.com/id/1040831](http://www.securitytracker.com/id/1040831), [https://0patch.blogspot.si/2018/02/two-interesting-micropatches-for-7-zip.html](https://0patch.blogspot.si/2018/02/two-interesting-micropatches-for-7-zip.html), [https://landave.io/2018/01/7-zip-multiple-memory-corruptions-via-rar-and-zip/](https://landave.io/2018/01/7-zip-multiple-memory-corruptions-via-rar-and-zip/)