Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.BUGS.DIST
  • Bug#1109494: 7zip: CVE-2025-53816 CVE-2025-53817

    From Salvatore Bonaccorso@21:1/5 to All on Sat Jul 19 07:50:01 2025
    Source: 7zip
    Version: 24.09+dfsg-8
    Severity: grave
    Tags: security upstream
    X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

    Hi,

    The following vulnerabilities were published for 7zip.

    CVE-2025-53816[0]:
    | 7-Zip is a file archiver with a high compression ratio. Zeroes
    | written outside heap buffer in RAR5 handler may lead to memory
    | corruption and denial of service in versions of 7-Zip prior to
    | 25.0.0. Version 25.0.0 contains a fix for the issue.


    CVE-2025-53817[1]:
    | 7-Zip is a file archiver with a high compression ratio. 7-Zip
    | supports extracting from Compound Documents. Prior to version
    | 25.0.0, a null pointer dereference in the Compound handler may lead
    | to denial of service. Version 25.0.0 contains a fix cor the issue.


    If you fix the vulnerabilities please also make sure to include the
    CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

    For further information see:

    [0] https://security-tracker.debian.org/tracker/CVE-2025-53816
    https://www.cve.org/CVERecord?id=CVE-2025-53816
    https://securitylab.github.com/advisories/GHSL-2025-058_7-Zip/
    [1] https://security-tracker.debian.org/tracker/CVE-2025-53817
    https://www.cve.org/CVERecord?id=CVE-2025-53817
    https://securitylab.github.com/advisories/GHSL-2025-059_7-Zip/

    Please adjust the affected versions in the BTS as needed.

    Regards,
    Salvatore

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • Who's Online

  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 39:59:01
    Calls: 12,109
    Files: 15,006
    Messages: 6,518,395

© >>> Magnum BBS <<<, 2026