Impact
PeaZip’s PEA extraction routine has an out‑of‑bounds write that lets an attacker, by convincing a user to open or extract a specially crafted .pea file, execute arbitrary code as the user running PeaZip. The vulnerability is triggered during decompression of the first PCOMPRESS1 block, where the 32‑bit compressed‑block‑size field is read directly from the file and used as the length to fill fixed‑size global buffers without validation. The overflow can overwrite adjacent global data, and researchers demonstrated code execution on official Linux x86‑64 and Windows x64 builds, confirming the impact across multiple platforms with no extra configuration or password required.
Affected Systems
The flaw is present in PeaZip 11.2.0 and earlier versions. It affects all supported operating systems, including Windows, macOS, Linux, and BSD, and applies to any user who opens or extracts a malicious .pea archive with these versions.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity flaw, and the EPSS is currently not available, so the exact likelihood of exploitation is unknown, but the vulnerability is listed as a serious risk. It is not part of the CISA KEV catalog. The attack vector is local, relying on social engineering or a user who knowingly opens a malicious archive; the attacker can achieve full code execution as the running user and potentially compromise the entire system. Because the bug involves an unchecked out‑of‑bounds write and copy loop, it can be exploited without additional privileges or exotic conditions.
OpenCVE Enrichment