Untrusted search path vulnerability in Self-extracting archive files created by 7-ZIP32.DLL 9.22.00.01 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Link | Tags |
---|---|
http://akky.xrea.jp/security/7-zip4.txt | vendor advisory |
http://www.securityfocus.com/bid/96431 | vdb entry third party advisory |
http://jvn.jp/en/jp/JVN86200862/index.html | vdb entry third party advisory |