this post was submitted on 30 Dec 2024
1 points (66.7% liked)

Cybersecurity

75 readers
79 users here now

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Rules

Community Rules

founded 2 years ago
MODERATORS
 

๐Ÿšจ SECURITY PSA - 7ZIP VULN๐Ÿšจ

Update your 7zip, folks

https://cybersecuritynews.com/7-zip-vulnerability-arbitrary-code/

#cybersecurity #zeroday #7zip #malware #security #it #infosec

top 9 comments
sorted by: hot top controversial new old
[โ€“] [email protected] 2 points 2 weeks ago (1 children)

@neatchee Thanks for the warning. I make a lot of use of 7-Zip.

Zstandard is used in a lot of things. This could be problematic as a whole.

[โ€“] [email protected] 1 points 2 weeks ago (1 children)

@[email protected] supply chain attacks are the favorite these days :/

[โ€“] [email protected] 1 points 2 weeks ago

@neatchee Sadly an all too accurate statement.

Luckily the version of 7-Zip with the fix was back in August, so I'm guessing this CVE has been well known across most things. Each of my Linux systems were probably ok by the time I installed the current versions even (let alone updates.)

I did need to update the Windows partition though. Haven't booted it in ages, much less updated 7-Zip...

[โ€“] [email protected] 2 points 2 weeks ago (1 children)

@neatchee
If you read the write up, it sounds like the 7-Zip maintainers have not released a version yet with a patch. Current release is 24.09... watch for something newer.

[โ€“] [email protected] 1 points 2 weeks ago (1 children)

@[email protected] CVE indicates 24.08 was the patched version

[โ€“] [email protected] 1 points 2 weeks ago

@neatchee That good to know. The original report from the group that found it said they were unaware of any patched version being released, but they had not heard from the maintainers yet. I usually check for an update once a month anyway.

[โ€“] [email protected] 2 points 2 weeks ago

@neatchee it's a fake proof of concept https://therecord.media/fake-zero-day-7Zip

[โ€“] TootSweet 1 points 2 weeks ago (1 children)

Why do I hear specifically about vulnerabilities in compression programs so much more than in other kinds of software?

[โ€“] [email protected] 2 points 2 weeks ago

@[email protected] because it's specifically software that is about opening and processing arbitrary payloads.