NULL pointer dereference in p7zip - CVE-2016-9296
Published: August 3, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in function CInArchive::ReadAndDecodePackedStreams in CPP/7zip/Archive/7z/7zIn.cpp, as used in the 7z.so library and in 7z applications. A remote attacker can perform a denial of service (DoS) attack via a specially crafted 7z file.
Affected software
Fedora
openEuler
p7zip
linux-firmware (Alpine package)
How to mitigate CVE-2016-9296
p7zip - update to 16.02-3
linux-firmware (Alpine package) - update to 20180615-r2