Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
Link | Tags |
---|---|
https://www.7-zip.org/download.html | product |
https://www.zerodayinitiative.com/advisories/ZDI-23-1165/ | third party advisory vdb entry |
https://sourceforge.net/p/sevenzip/discussion/45797/thread/713c8a8269/ | release notes issue tracking |
https://security.netapp.com/advisory/ntap-20231110-0007/ | third party advisory |
https://ds-security.com/post/integer-overflow-in-7-zip-cve-2023-31102/ |