VDB

MAGEIA-2021-305

MAGEIA-2021-305 PUBLISHED

In p7zip-17.03, the function NCompress::CCopyCoder::Code in CPP/7zip/Common/StreamObjects.cpp will call outStream->Write where a memcpy uses a NULL pointer as destination address, leading to a crash (CVE-2021-3465). Null pointer dereference in function Reserve() found in p7zip 16.02 (rhbz#1951218). Null Pointer Dereference in function NArchive::NLzh::CItem::GetUnixTime found in p7zip 16.02 (rhbz#1951224). The p7zip package has been patched to fix these issues. Also, the Mageia 7 package has been updated to version 17.03.

Affected Products

VendorProductVersions
Mageiap7zip0, 17.03-1.1.mga8
Mageiap7zip0, 17.03-1.1.mga7

Timeline

  • Jun 30, 2021 CVE Updated
  • Jun 30, 2021 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›