Project64: 7-zip lib security issues

Created on 14 May 2016  路  3Comments  路  Source: project64/project64

Two vulnerabilities recently patched in 7-Zip could put at risk of compromise many software products and devices that bundle the open-source file archiving library.

The flaws, an out-of-bounds read vulnerability and a heap overflow, were discovered by researchers from Cisco's Talos security team. They were fixed in 7-Zip 16.00, released Tuesday.

The 7-Zip software can pack and unpack files using a large number of archive formats, including its own 7z format, which is more efficient than ZIP. Its versatility and open-source nature make it an attractive library to include in other software projects that need to process and deal with archived files.

Previous research has shown that most developers do a poor job of keeping track of vulnerabilities in the third-party code they use and that they rarely update the libraries included in their projects.

"7-Zip is supported on all major platforms, and is one of the most popular archive utilities in-use today," the Cisco Talos researchers said in a blog post. "Users may be surprised to discover just how many products and appliances are affected."

A search on Google reveals that 7-Zip is used in many software projects, including in security devices and antivirus products. Many custom enterprise applications also likely use it.

The out-of-bounds read vulnerability, tracked as CVE-2016-2335, stems from 7-Zip's handling of Universal Disk Format (UDF) files, while the heap overflow condition, CVE-2016-2334, can occur when handling zlib compressed files.

To exploit the flaws, attackers can craft specially crafted files in those formats and deliver them in a way that would cause the vulnerable 7-Zip code to process them.

Source:
http://www.pcworld.com/article/3069975/dangerous-7-zip-flaws-put-many-other-software-products-at-risk.html

http://blog.talosintel.com/2016/05/multiple-7-zip-vulnerabilities.html

Most helpful comment

I'd just rename this to: "Patch Project64 zlib to address security issues".

All 3 comments

I'd just rename this to: "Patch Project64 zlib to address security issues".

@project64 @Lithium64 @JunielKatarn We are using version 9.20 right now, we desperately need to upgrade to 16.04. There have been so many bug fixes, security improvements, and performance improvements it really would be worth it.

closing old issue, if this is still an issue it can be reopened

Was this page helpful?
0 / 5 - 0 ratings

Related issues

Rikimaruaxu picture Rikimaruaxu  路  5Comments

waitingmoon picture waitingmoon  路  11Comments

vgturtle127 picture vgturtle127  路  18Comments

Frank-74 picture Frank-74  路  17Comments

dsx- picture dsx-  路  15Comments