#14867 closed enhancement (fixed)
Fix CVE-2021-3465 in p7zip
| Reported by: | Douglas R. Reno | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | elevated | Milestone: | 11.0 |
| Component: | BOOK | Version: | SVN |
| Severity: | medium | Keywords: | |
| Cc: |
Description
Additional information from Arch:
In p7zip 17.03, the function NCompress::CCopyCoder::Code in CPP/7zip/Common/StreamObjects.cpp will call outStream->Write where a memcpy uses a NULL pointer as destination address, leading to a crash.
https://github.com/jinfeihan57/p7zip/commit/295dac87f657de12f6165cb9d81404e079651a50
Change History (5)
comment:1 by , 6 years ago
| Priority: | normal → elevated |
|---|
comment:2 by , 6 years ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:4 by , 5 years ago
The CVE has been withdrawn by the CNA, so I will not file a security advisory for this.
Note:
See TracTickets
for help on using tickets.

I found a way to do these all via seds. They will be in my next commit.