7-Zip CopyCoder Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of 7-Zip. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.
The specific flaw exists within the processing of streams. The issue results from a logic error that can lead to an infinite loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-24307.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.zerodayinitiative.com/advisories/ZDI-24-1606/ |
History
Tue, 26 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 22 Nov 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | 7-Zip CopyCoder Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of 7-Zip. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of streams. The issue results from a logic error that can lead to an infinite loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-24307. | |
Title | 7-Zip CopyCoder Infinite Loop Denial-of-Service Vulnerability | |
Weaknesses | CWE-835 | |
References |
| |
Metrics |
cvssV3_0
|
MITRE
Status: PUBLISHED
Assigner: zdi
Published: 2024-11-22T20:22:10.629Z
Updated: 2024-11-26T15:13:29.515Z
Reserved: 2024-11-21T20:34:17.530Z
Link: CVE-2024-11612
Vulnrichment
Updated: 2024-11-26T15:12:50.443Z
NVD
Status : Received
Published: 2024-11-22T21:15:17.387
Modified: 2024-11-22T21:15:17.387
Link: CVE-2024-11612
Redhat
No data.