VYPR

rpm package

opensuse/7zip&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/7zip&distro=openSUSE%20Tumbleweed

Vulnerabilities (3)

  • CVE-2026-48095HigJun 5, 2026
    affected < 26.01-1.1fixed 26.01-1.1

    7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation in the NTFS compressed stream buffer (GetCuSize shift UB), potentially allowing attackers to cause arbitrary code execution

  • CVE-2025-53816HigJul 17, 2025
    affected < 25.01-1.1fixed 25.01-1.1

    7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to memory corruption and denial of service in versions of 7-Zip prior to 25.0.0. Version 25.0.0 contains a fix for the issue.

  • CVE-2025-53817Jul 17, 2025
    affected < 25.01-1.1fixed 25.01-1.1

    7-Zip is a file archiver with a high compression ratio. 7-Zip supports extracting from Compound Documents. Prior to version 25.0.0, a null pointer dereference in the Compound handler may lead to denial of service. Version 25.0.0 contains a fix cor the issue.