CVE-2024-11612

NameCVE-2024-11612
Description7-Zip CopyCoder Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of 7-Zip. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of streams. The issue results from a logic error that can lead to an infinite loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-24307.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
7zip (PTS)bookworm22.01+dfsg-8+deb12u1vulnerable
sid, trixie24.09+dfsg-2fixed
p7zip (PTS)jessie, jessie (lts)9.20.1~dfsg.1-4.1+deb8u3vulnerable
stretch (security), stretch (lts), stretch16.02+dfsg-3+deb9u1vulnerable
buster16.02+dfsg-6vulnerable
bullseye, bookworm16.02+dfsg-8vulnerable
sid, trixie16.02+transitional.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
7zipsource(unstable)24.08+dfsg-1unimportant
p7zipsource(unstable)16.02+transitional.1unimportant

Notes

Crash in CLI tool, no security impact
https://www.zerodayinitiative.com/advisories/ZDI-24-1606/
https://bushido-sec.com/index.php/2024/11/22/2ourc3-vulnerabiltiy-7zip-fuzzing/
Since p7zip/16.02+transitional.1 src:p7zip is only a empty source package
depending on 7zip. Mark this version as fixed version.

Search for package or bug name: Reporting problems