CVE-2018-5996 PUBLISHED

Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory corruptions within the PPMd code, allows remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.

EPSS 4.48% · 89.0th percentile

Risk Scores

EPSS Score
4.48%
89.0th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSp7zip-rar0, 9.20.1~ds.1-3, 9.20.1~ds.1-4

Timeline

References

Open in Interactive Console →