Monday, September 25, 2023
Kiratas
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
Kiratas
No Result
View All Result
Home World

Update now! High-risk vulnerabilities in 7-Zip allow code smuggling

Eliza Houghton by Eliza Houghton
August 29, 2023
in World
0
Update now!  High-risk vulnerabilities in 7-Zip allow code smuggling
0
SHARES
30
VIEWS
Share on FacebookShare on Twitter

The 7-Zip archive tool uses updated installation packages to close two security gaps that attackers can use to inject malicious code into victims. Opening carefully prepared files is sufficient for this. Therefore, users should install the available update quickly.

Advertisement

Version 23.00 of 7-Zip, which was released at the end of May, already closes the security gaps. Version 23.01 from June is now current and available on the 7-Zip download page.

7-Zip: High-risk vulnerabilities

The Zero Day Initiative found and reported the gaps. On the one hand, the parser for SquashFS file images can write outside the allocated memory areas because it does not sufficiently check the data passed. Attackers can exploit the vulnerability by tricking victims into opening modified files (CVE-2023-40481, CVSS 7.8, risk “high”).

However, when processing 7-Zip archives, integer underflow can occur because the code does not adequately validate and filter values ​​within before using them. Prepared archives can also trigger the error (CVE-2023-31102, CVSS 7.8, high).

The 7-Zip version 23.00 changelog does not mention fixing security vulnerabilities. Since version 23.01 is now available, you should update to this version right away.

No automatic update

Advertisement

7-Zip does not have an integrated update mechanism, neither to trigger manually nor an automatic version. Therefore, 7-Zip users must download and run the installation package themselves to update the software to the corrected state. Under Linux, on the other hand, the software management of the distribution used helps with the update search and installation.

Vulnerabilities in the WinRAR archiving program have only recently become known. Here, too, attackers could have foisted malicious code on victims with manipulated files.

(dmk)

Go to home page
#Update #Highrisk #vulnerabilities #7Zip #code #smuggling

Tags: 7-Zip7ZipCodehighriskSecuritySecurity gapsSecurity updatessmugglingUpdateVulnerabilities
Previous Post

Google TPU: AI chip calculates its own successor

Next Post

The priest of Rubiales’ mother’s church: “But what is this?”

Eliza Houghton

Eliza Houghton

Related Posts

Fighting in hell: The Ukrainian soldiers who liberated Andriivka
World

Fighting in hell: The Ukrainian soldiers who liberated Andriivka

by Eliza Houghton
September 25, 2023
SpamSieve 3.0: Complete conversion due to macOS Sonoma
World

SpamSieve 3.0: Complete conversion due to macOS Sonoma

by Eliza Houghton
September 25, 2023
Restoration teams recover nearly 20 more bodies in Derna
World

Restoration teams recover nearly 20 more bodies in Derna

by Eliza Houghton
September 25, 2023
Japan Weekend takes over Madrid (And Super Mario takes Japan Weekend)
World

Japan Weekend takes over Madrid (And Super Mario takes Japan Weekend)

by Eliza Houghton
September 25, 2023
iPhone 15: Bug in iOS 17 prevents data transfer from old device
World

iPhone 15: Bug in iOS 17 prevents data transfer from old device

by Eliza Houghton
September 25, 2023
Next Post
The priest of Rubiales’ mother’s church: “But what is this?”

The priest of Rubiales' mother's church: "But what is this?"

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

Premium Content

Josu Ternera to his friend Évole: “The civil guards knew that they risked dying for their country”

Josu Ternera to his friend Évole: “The civil guards knew that they risked dying for their country”

September 22, 2023
Last minute of the Women’s National Soccer Team live |  Montse Tomé’s list and decision of the summoned players

Last minute of the Women’s National Soccer Team live | Montse Tomé’s list and decision of the summoned players

September 19, 2023
Syria, Russian attack on a jihadist military base

Syria, Russian attack on a jihadist military base

August 21, 2023

Browse by Category

  • Science
  • Sports
  • World

Browse by Tags

Apple Artificial Intelligence attacks China Court Cup data Death due Feijóo Germany Google government investiture iOS iPhone law live Madrid man Microsoft million news people police President Rubiales Russia Russia-Ukraine invasion Security Security gaps Software development Spain Spanish Sánchez time Today Ukraine Updates video Vulnerabilities war workshop world years
Kiratas

Latest News from World, Health, Politics, Sports, Business, Education, Technology, Arts and Latin America, the Middle East, South Asia.

Categories

  • Science
  • Sports
  • World

Browse by Tag

Apple Artificial Intelligence attacks China Court Cup data Death due Feijóo Germany Google government investiture iOS iPhone law live Madrid man Microsoft million news people police President Rubiales Russia Russia-Ukraine invasion Security Security gaps Software development Spain Spanish Sánchez time Today Ukraine Updates video Vulnerabilities war workshop world years

Recent Posts

  • Fighting in hell: The Ukrainian soldiers who liberated Andriivka
  • SpamSieve 3.0: Complete conversion due to macOS Sonoma
  • Restoration teams recover nearly 20 more bodies in Derna
  • About Us
  • Home
  • Privacy Policy
  • Terms and Conditions

© Aroged 2023. All Rights Reserved.

No Result
View All Result
  • Home
  • Landing Page
  • Buy JNews
  • Support Forum
  • Contact Us

© Aroged 2023. All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.