CVE-2016-2334
Summary
| CVE | CVE-2016-2334 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-12-13 22:59:00 UTC |
| Updated | 2023-11-07 02:31:00 UTC |
| Description | Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HFS+ image. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 24 Update: p7zip-16.02-1.fc24 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| Cisco's Talos Intelligence Group Blog: Vulnerability Walkthrough: 7zip CVE-2016-2334 HFS+ Code Execution Vulnerability |
MISC |
blog.talosintelligence.com |
|
| 7-Zip Buffer Overflow and Memory Read Error in Processing Files Lets Remote Users Execute Arbitrary Code - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| Cisco Talos Blog: Multiple 7-Zip Vulnerabilities Discovered by Talos |
MISC |
blog.talosintel.com |
Exploit, Third Party Advisory |
| [SECURITY] Fedora 23 Update: p7zip-16.02-1.fc23 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Cisco Talos - Talos 2016 0093 |
MISC |
www.talosintel.com |
Exploit, Third Party Advisory |
| 7-Zip: Multiple vulnerabilities (GLSA 201701-27) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| 90531 |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| [SECURITY] Fedora 24 Update: p7zip-16.02-1.fc24 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 23 Update: p7zip-16.02-1.fc23 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| Oracle Solaris Bulletin - October 2016 |
CONFIRM |
www.oracle.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710386 Gentoo Linux 7-Zip Multiple Vulnerabilities (GLSA 201701-27)