CVE-2023-52169

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-52169
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-52169.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-52169
Downstream
Related
Published
2024-07-03T18:15:04Z
Modified
2025-08-09T20:01:27Z
Summary
[none]
Details

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.

References

Affected packages