VYPR
High severity8.8NVD Advisory· Published Jun 7, 2016· Updated May 6, 2026

CVE-2016-2335

CVE-2016-2335

Description

The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to cause a denial of service (out-of-bounds read) or execute arbitrary code via the PartitionRef field in the Long Allocation Descriptor in a UDF file.

Affected products

5
  • cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • 7 Zip/7 Zip2 versions
    cpe:2.3:a:7-zip:7-zip:9.20:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:7-zip:7-zip:9.20:*:*:*:*:*:*:*
    • cpe:2.3:a:7-zip:7-zip:15.05:beta:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

13

News mentions

0

No linked articles in our index yet.