CVE-2023-52168

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite two bytes at multiple offsets beyond the allocated buffer size: buffer+512*i-2, for i=9, i=10, i=11, etc.
Configurations

No configuration.

History

21 Nov 2024, 08:39

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2024/07/03/10 - () http://www.openwall.com/lists/oss-security/2024/07/03/10 -
References () https://dfir.ru/2024/06/19/vulnerabilities-in-7-zip-and-ntfs3/ - () https://dfir.ru/2024/06/19/vulnerabilities-in-7-zip-and-ntfs3/ -
References () https://sourceforge.net/p/sevenzip/bugs/2402/ - () https://sourceforge.net/p/sevenzip/bugs/2402/ -
References () https://www.openwall.com/lists/oss-security/2024/07/03/10 - () https://www.openwall.com/lists/oss-security/2024/07/03/10 -

12 Jul 2024, 16:11

Type Values Removed Values Added
CWE CWE-122
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.4

05 Jul 2024, 23:15

Type Values Removed Values Added
References
  • () https://dfir.ru/2024/06/19/vulnerabilities-in-7-zip-and-ntfs3/ -

05 Jul 2024, 12:55

Type Values Removed Values Added
Summary
  • (es) El controlador NTFS NtfsHandler.cpp en 7-Zip anterior a 24.01 (para 7zz) contiene un desbordamiento de búfer basado en montón que permite a un atacante sobrescribir dos bytes en múltiples desplazamientos más allá del tamaño de búfer asignado: búfer+512*i-2, para i =9, yo=10, yo=11, etc.

03 Jul 2024, 19:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/07/03/10 -

03 Jul 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-03 18:15

Updated : 2024-11-21 08:39


NVD link : CVE-2023-52168

Mitre link : CVE-2023-52168

CVE.ORG link : CVE-2023-52168


JSON object : View

Products Affected

No product.

CWE
CWE-122

Heap-based Buffer Overflow