CVE-2016-2335

Published: July 6, 2016
The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to cause a denial of service (out-of-bounds read) or execute arbitrary code via the PartitionRef field in the Long Allocation Descriptor in a UDF file.
HIGH
CVSS v3: 8.8

Status

DocFilters Release Package State Justification Comment
25.1 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
24.4 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
24.4.0 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
24.3 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
24.2.1 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
24.2 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
24.1 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
23.3 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
23.2.1 7-zip (17.01) Not Affected Protected At Runtime CVE does not included required value ‘lzma’
23.2 7-zip (17.01) Not Affected Protected At Runtime CVE does not included required value ‘lzma’
23.1 7-zip (17.01) Not Affected Protected At Runtime CVE does not included required value ‘lzma’
22.4 7-zip (17.01) Not Affected Protected At Runtime CVE does not included required value ‘lzma’

Severity score breakdown

Attack Complexity
LOW
Attack Vector
NETWORK
Availability Impact
HIGH
Base Score
8.8
Base Severity
HIGH
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Privileges Required
NONE
Scope
UNCHANGED
User Interaction
REQUIRED
Vector String
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Version
3.0

References