First published: Tue Apr 15 2025(Updated: )
Igor Pavlov discovered that 7-Zip had several memory-related issues. An attacker could possibly use these issues to cause 7-Zip to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2023-52168, CVE-2023-52169)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/7zip | <23.01+dfsg-11ubuntu0.1~esm1 | 23.01+dfsg-11ubuntu0.1~esm1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/7zip-standalone | <23.01+dfsg-11ubuntu0.1~esm1 | 23.01+dfsg-11ubuntu0.1~esm1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/7zip | <21.07+dfsg-4ubuntu0.1~esm1 | 21.07+dfsg-4ubuntu0.1~esm1 |
Ubuntu | =22.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-7438-1 is high due to multiple memory-related issues in 7-Zip that could lead to denial of service or arbitrary code execution.
To fix USN-7438-1, upgrade 7-Zip to version 23.01+dfsg-11ubuntu0.1~esm1 or 21.07+dfsg-4ubuntu0.1~esm1 depending on your Ubuntu version.
USN-7438-1 affects 7-Zip and 7zip-standalone packages on Ubuntu versions 22.04 and 24.04.
The CVEs associated with USN-7438-1 are CVE-2023-52168 and CVE-2023-52169.
An attacker exploiting USN-7438-1 could cause the 7-Zip application to crash or potentially execute arbitrary code.