Bugzilla – Bug 1209648
VUL-0: CVE-2022-47069: p7zip: Heap buffer overflow in ZipIn.cpp
Last modified: 2024-06-27 10:25:58 UTC
CVE-2023-1576 A Heap-buffer-overflow in CPP/7zip/Archive/Zip/ZipIn.cpp:1116 in NArchive::NZip::CInArchive::FindCd(bool) was found in p7zip 16.02. References: https://sourceforge.net/p/p7zip/bugs/241/ References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-1576 https://bugzilla.redhat.com/show_bug.cgi?id=2180876
I think there is not fix upstream yet
Affected: - SUSE:SLE-15-SP2:Update/p7zip 16.02 - SUSE:SLE-15:Update/p7zip 16.02 Not Affected: - SUSE:SLE-11-SP3:Update/p7zip 9.20.1 - SUSE:SLE-12:Update/p7zip 9.20.1
Upstream hasn't provided a fix yet, unfortunately.
*** Bug 1216265 has been marked as a duplicate of this bug. ***