CVE-2018-5996

CVSS 3.0 Score 7.8 of 10 (high)

Details

Published Jan 31, 2018
Updated: Jan 10, 2025
CWE ID 119

Summary

CVE-2018-5996 is a memory corruption vulnerability affecting the 7-Zip and p7zip software before version 18.00. The issue lies within the NCompress::NRar3::CDecoder::Code method of these applications, where insufficient exception handling can lead to multiple memory corruption incidents in the PPMd code. A remote attacker can exploit this flaw by providing a specially crafted RAR archive, which can result in a denial of service due to a segmentation fault or potentially execute arbitrary code.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share