Bug 979823 (CVE-2016-2335) - VUL-0: CVE-2016-2335: p7zip UDF CInArchive::ReadFileItem Code Execution Vulnerability
Summary: VUL-0: CVE-2016-2335: p7zip UDF CInArchive::ReadFileItem Code Execution Vulne...
Status: RESOLVED FIXED
Alias: CVE-2016-2335
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: x86-64 Other
: P3 - Medium : Major
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: CVSSv2:RedHat:CVE-2016-2335:5.1:(AV:N...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-05-13 00:01 UTC by Mikhail Kasimov
Modified: 2021-06-07 09:55 UTC (History)
2 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Mikhail Kasimov 2016-05-13 00:01:20 UTC
CVE-2016-2335: 7zip UDF CInArchive::ReadFileItem Code Execution Vulnerability

Described on: http://www.talosintel.com/reports/TALOS-2016-0094/

===========
Tested Versions

7-Zip [32] 15.05 beta
7-Zip [64] 9.20
           ^^^^^^-- is in all openSUSE versions, including Tumbleweed. (http://software.opensuse.org/package/p7zip)
Comment 1 Swamp Workflow Management 2016-05-13 22:00:27 UTC
bugbot adjusting priority
Comment 2 Kristyna Streitova 2016-05-16 13:48:09 UTC
Fixed in 7-Zip 16.00 (2016-05-10)

Patch:
https://sourceforge.net/p/p7zip/discussion/383043/thread/9d0fb86b/#1dba

(In reply to Mikhail Kasimov from comment #0)
> 7-Zip [64] 9.20
>            ^^^^^^-- is in all openSUSE version, including Tumbleweed.

Please note that we have version 15.14.1 in Tumbleweed [1]. 

The fix is already on the way to Factory [2].


[1] https://build.opensuse.org/package/show/openSUSE:Factory/p7zip
[2] https://build.opensuse.org/request/show/395152
Comment 4 Kristyna Streitova 2016-05-24 15:19:55 UTC
Summary of the submissions:

|     Codestream     | Version | Affected | Request # |
|--------------------|---------|----------|-----------|
| SUSE:SLE-12:Update | 9.20.1  | yes      | #115117   |
| openSUSE:13.2      | 9.20.1  | yes      | #397731   |
| openSUSE:Leap:42.1 | 9.20.1  | yes      | via SLE12 |
| openSUSE:Factory   | 15.14.1 | yes      | #395152   |


All done, reassigning to the security team.
Comment 5 Bernhard Wiedemann 2016-05-24 16:00:16 UTC
This is an autogenerated message for OBS integration:
This bug (979823) was mentioned in
https://build.opensuse.org/request/show/397731 13.2 / p7zip
Comment 7 Swamp Workflow Management 2016-06-01 13:10:12 UTC
openSUSE-SU-2016:1464-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 979823
CVE References: CVE-2016-2335
Sources used:
openSUSE 13.2 (src):    p7zip-9.20.1-12.6.1
Comment 8 Swamp Workflow Management 2016-06-16 09:08:33 UTC
SUSE-SU-2016:1593-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 979823
CVE References: CVE-2016-2335
Sources used:
SUSE Linux Enterprise Server 12-SP1 (src):    p7zip-9.20.1-6.1
SUSE Linux Enterprise Server 12 (src):    p7zip-9.20.1-6.1
SUSE Linux Enterprise Desktop 12-SP1 (src):    p7zip-9.20.1-6.1
SUSE Linux Enterprise Desktop 12 (src):    p7zip-9.20.1-6.1
Comment 9 Marcus Meissner 2016-06-16 14:47:50 UTC
rekleased
Comment 10 Swamp Workflow Management 2016-06-24 14:30:33 UTC
openSUSE-SU-2016:1675-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 979823
CVE References: CVE-2016-2335
Sources used:
openSUSE Leap 42.1 (src):    p7zip-9.20.1-15.1
Comment 11 Bernhard Wiedemann 2016-07-20 16:00:35 UTC
This is an autogenerated message for OBS integration:
This bug (979823) was mentioned in
https://build.opensuse.org/request/show/412356 13.1 / p7zip
Comment 12 Swamp Workflow Management 2016-07-22 00:08:59 UTC
openSUSE-SU-2016:1850-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 979823
CVE References: CVE-2016-2335
Sources used:
openSUSE 13.1 (src):    p7zip-9.20.1-10.6.1