#VU118786 Out-of-bounds read in p7zip - CVE-2022-47069
Published: November 26, 2025
p7zip
p7zip.sourceforge.net
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the NArchive::NZip::CInArchive::FindCd() function in CPP/7zip/Archive/Zip/ZipIn.cpp. A remote attacker can create a specially crafted archive, trick the victim into opening it, trigger an out-of-bounds read error and read contents of memory on the system.