CVE-2018-10115

Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.
Configurations

Configuration 1 (hide)

cpe:2.3:a:7-zip:7-zip:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:40

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/104132 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/104132 - Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1040832 - Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1040832 - Third Party Advisory, VDB Entry
References () https://landave.io/2018/05/7-zip-from-uninitialized-memory-to-remote-code-execution/ - Exploit, Third Party Advisory () https://landave.io/2018/05/7-zip-from-uninitialized-memory-to-remote-code-execution/ - Exploit, Third Party Advisory
References () https://sourceforge.net/p/sevenzip/discussion/45797/thread/adc65bfa/ - Issue Tracking () https://sourceforge.net/p/sevenzip/discussion/45797/thread/adc65bfa/ - Issue Tracking

Information

Published : 2018-05-02 21:29

Updated : 2024-11-21 03:40


NVD link : CVE-2018-10115

Mitre link : CVE-2018-10115

CVE.ORG link : CVE-2018-10115


JSON object : View

Products Affected

7-zip

  • 7-zip
CWE
CWE-665

Improper Initialization

CWE-908

Use of Uninitialized Resource