CVE-2016-2334 is a heap-based buffer overflow vulnerability in 7-Zip versions prior to 16.00 and p7zip, specifically within the NArchive::NHfs::CHandler::ExtractZlibFile method. This flaw allows remote attackers to execute arbitrary code by tricking a user into opening a specially crafted HFS+ image. With a CVSS score of 7.8 (High), it presents a significant risk due to its high impact on confidentiality, integrity, and availability, requiring user interaction but being low complexity to exploit. While not listed in CISA's KEV catalog, its high FAUCET Risk Score of 85/100, notable media coverage, and community discussion suggest it was a well-known and concerning vulnerability at the time, though no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 15.14CPE matchmatch criteria | cpe:2.3:a:7-zip:7-zip:*:*:*:*:*:*:*:* | ||
23CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:* | ||
24CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:oracle:solaris:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.