DEBIAN-CVE-2023-52169

Source
https://security-tracker.debian.org/tracker/CVE-2023-52169
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-52169.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2023-52169
Upstream
Published
2024-07-03T18:15:04Z
Modified
2025-10-10T19:30:27.168326Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H CVSS Calculator
Summary
[none]
Details

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.

References

Affected packages

Debian:11

p7zip

Package

Name
p7zip
Purl
pkg:deb/debian/p7zip?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

16.*

16.02+dfsg-8
16.02+transitional.1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12

7zip

Package

Name
7zip
Purl
pkg:deb/debian/7zip?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
22.01+dfsg-8+deb12u1

Affected versions

22.*

22.01+dfsg-8

Ecosystem specific

{
    "urgency": "not yet assigned"
}

p7zip

Package

Name
p7zip
Purl
pkg:deb/debian/p7zip?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

16.*

16.02+dfsg-8
16.02+transitional.1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13

7zip

Package

Name
7zip
Purl
pkg:deb/debian/7zip?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
24.05+dfsg-1

Ecosystem specific

{
    "urgency": "unimportant"
}

p7zip

Package

Name
p7zip
Purl
pkg:deb/debian/p7zip?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
16.02+transitional.1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:14

7zip

Package

Name
7zip
Purl
pkg:deb/debian/7zip?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
24.05+dfsg-1

Ecosystem specific

{
    "urgency": "unimportant"
}