CVE-2017-17969 is a heap-based buffer overflow vulnerability in the NCompress::NShrink::CDecoder::CodeReal method of 7-Zip before version 18.00 and p7zip. This flaw allows remote attackers to cause a denial of service or potentially execute arbitrary code through a specially crafted ZIP archive. With a CVSS score of 7.8 (HIGH), it has a low attack complexity and requires user interaction, potentially leading to high impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, nor are there public exploit modules available in Metasploit or ExploitDB, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.00CPE matchmatch criteria | cpe:2.3:a:7-zip:7-zip:*:*:*:*:*:*:*:* | ||
< 18.0CPE matchmatch criteria | cpe:2.3:a:7-zip:p7zip:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2017-17969
Jun 11, 2024CVE-2017-17969
Dec 14, 2021p7zip: heap-based buffer overflow in 7zip/Compress/ShrinkDecoder.cpp can allow an attacker to write arbitrary data and cause a crash
Jan 25, 2018Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to cause a denial of service (out-of-bounds write) or potentially execute arbitrary code via a crafted ZIP archive.
Jan 9, 2018