﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
20251	Apply fixes for CVE-2023-52168 and CVE-2023-52169 to p7zip	Douglas R. Reno	Douglas R. Reno	"We need to apply patches for CVE-2023-52168 and CVE-2023-52169 to p7zip. I found the patches at OpenSUSE: [https://build.opensuse.org/package/show/openSUSE:Leap:15.6/p7zip]

The vulnerabilities have been rated as High (8.2), and allow for remote code execution. 

CVE-2023-52168: ""The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite two bytes at multiple offsets beyond the allocated buffer size: buffer+512*i-2, for i=9, i=10, i=11, etc. ""

CVE-2023-52169: ""The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process."""	enhancement	closed	high	12.2	BOOK	git	blocker	fixed		
