NULL pointer dereference in p7zip - CVE-2016-9296
Published: August 3, 2020
p7zip
p7zip.sourceforge.net
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in function CInArchive::ReadAndDecodePackedStreams in CPP/7zip/Archive/7z/7zIn.cpp, as used in the 7z.so library and in 7z applications. A remote attacker can perform a denial of service (DoS) attack via a specially crafted 7z file.