CVE-2017-17969 PUBLISHED

Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to cause a denial of service (out-of-bounds write) or potentially execute arbitrary code via a crafted ZIP archive.

EPSS 3.26% · 87.0th percentile

Risk Scores

EPSS Score
3.26%
87.0th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSp7zip0, 9.20.1~dfsg.1-4.2
Ubuntu:14.04:LTSp7zip0, 9.20.1~dfsg.1-4, 9.20.1~dfsg.1-4+deb7u1build0.14.04.1

Timeline

References

Open in Interactive Console →