Bug 1209648 (CVE-2022-47069, CVE-2023-1576) - VUL-0: CVE-2022-47069: p7zip: Heap buffer overflow in ZipIn.cpp
Summary: VUL-0: CVE-2022-47069: p7zip: Heap buffer overflow in ZipIn.cpp
Status: NEW
: 1216265 (view as bug list)
Alias: CVE-2022-47069, CVE-2023-1576
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Antonio Teixeira
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/360816/
Whiteboard: CVSSv3.1:SUSE:CVE-2022-47069:3.3:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2023-03-23 10:02 UTC by Cathy Hu
Modified: 2024-06-27 10:25 UTC (History)
6 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Cathy Hu 2023-03-23 10:02:13 UTC
CVE-2023-1576

A Heap-buffer-overflow in CPP/7zip/Archive/Zip/ZipIn.cpp:1116 in NArchive::NZip::CInArchive::FindCd(bool) was found in p7zip 16.02.

References:

https://sourceforge.net/p/p7zip/bugs/241/

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-1576
https://bugzilla.redhat.com/show_bug.cgi?id=2180876
Comment 1 Cathy Hu 2023-03-23 10:03:05 UTC
I think there is not fix upstream yet
Comment 2 Cathy Hu 2023-03-23 12:19:04 UTC
Affected:
- SUSE:SLE-15-SP2:Update/p7zip 16.02
- SUSE:SLE-15:Update/p7zip 16.02

Not Affected:
- SUSE:SLE-11-SP3:Update/p7zip 9.20.1
- SUSE:SLE-12:Update/p7zip 9.20.1
Comment 5 Danilo Spinella 2023-05-24 10:49:53 UTC
Upstream hasn't provided a fix yet, unfortunately.
Comment 8 Gabriele Sonnu 2023-12-19 10:16:38 UTC
*** Bug 1216265 has been marked as a duplicate of this bug. ***