CVE-2018-5996 is a high-severity vulnerability affecting 7-Zip versions prior to 18.00 and p7zip, stemming from insufficient exception handling in the RAR3 decoder. This flaw allows remote attackers to trigger memory corruption and potentially execute arbitrary code or cause a denial of service via a specially crafted RAR archive. With a CVSS score of 7.8, it requires user interaction (opening a malicious file) but could lead to full compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code, or Metasploit modules, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.00CPE matchmatch criteria | cpe:2.3:a:7-zip:7-zip:*:*:*:*:*:*:*:* | ||
< 18.0CPE matchmatch criteria | cpe:2.3:a:7-zip:p7zip:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2018-5996
Jun 11, 2024CVE-2018-5996
Dec 14, 2021p7zip: memory corruption in RAR decompression
Jan 23, 2018Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory corruptions within the PPMd code allows remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.
Jan 9, 2018