5
CVSSv2

CVE-2016-9296

Published: 12/11/2016 Updated: 29/11/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A null pointer dereference bug affects the 16.02 and many old versions of p7zip. A lack of null pointer check for the variable folders.PackPositions in function CInArchive::ReadAndDecodePackedStreams in CPP/7zip/Archive/7z/7zIn.cpp, as used in the 7z.so library and in 7z applications, will cause a crash and a denial of service when decoding malformed 7z files.

Vulnerable Product Search on Vulmon Subscribe to Product

7-zip p7zip 16.02

Vendor Advisories

Debian Bug report logs - #844344 p7zip: CVE-2016-9296: Null pointer dereference (in 7zIncpp) Package: src:p7zip; Maintainer for src:p7zip is Robert Luberda <robert@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 14 Nov 2016 16:03:01 UTC Severity: grave Tags: patch, security, upstream F ...

Github Repositories

This repository is for CVE bug report of p7zip only

7zip-null-pointer-dereference This repository is for CVE bug report(CVE-2016-9296) of p7zip only