Debian P7Zip-Rar vulnerabilities

3 known vulnerabilities affecting debian/p7zip-rar.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2025-53816MEDIUMCVSS 5.5fixed in 7zip-rar 25.00+ds-1 (forky)2025
CVE-2025-53816 [MEDIUM] CVE-2025-53816: 7zip-rar - 7-Zip is a file archiver with a high compression ratio. Zeroes written outside h... 7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to memory corruption and denial of service in versions of 7-Zip prior to 25.0.0. Version 25.0.0 contains a fix for the issue. Scope: local forky: resolved (fixed in 25.00+ds-1) sid: resolved (fixed in 25.00+ds-1) trixie: resolved (fixed in 25.00+ds-
debian
CVE-2018-10115HIGHCVSS 7.8fixed in p7zip-rar 16.02-3 (bookworm)2018
CVE-2018-10115 [HIGH] CVE-2018-10115: p7zip-rar - Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before ... Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive. Scope: local bookworm: resolved (fixed in 16.02-3) bullseye: resolved (fixed in 16.02-3) trixie: resolved (fixed i
debian
CVE-2018-5996HIGHCVSS 7.8fixed in p7zip-rar 16.02-2 (bookworm)2018
CVE-2018-5996 [HIGH] CVE-2018-5996: p7zip-rar - Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code o... Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory corruptions within the PPMd code, allows remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive. Scope: local bookworm: resolved (fixed in 16.02-2) bullseye: resolve
debian