🚨 SECURITY PSA - 7ZIP VULN🚨

Update your 7zip, folks

https://cybersecuritynews.com/7-zip-vulnerability-arbitrary-code/

#cybersecurity #zeroday #7zip #malware #security #it #infosec

2 points

@neatchee Thanks for the warning. I make a lot of use of 7-Zip.

Zstandard is used in a lot of things. This could be problematic as a whole.

permalink
report
reply
1 point

@nazokiyoubinbou@urusai.social supply chain attacks are the favorite these days :/

permalink
report
parent
reply
1 point

@neatchee Sadly an all too accurate statement.

Luckily the version of 7-Zip with the fix was back in August, so I’m guessing this CVE has been well known across most things. Each of my Linux systems were probably ok by the time I installed the current versions even (let alone updates.)

I did need to update the Windows partition though. Haven’t booted it in ages, much less updated 7-Zip…

permalink
report
parent
reply
2 points

@neatchee
If you read the write up, it sounds like the 7-Zip maintainers have not released a version yet with a patch. Current release is 24.09… watch for something newer.

permalink
report
reply
1 point

@devans143@phpc.social CVE indicates 24.08 was the patched version

permalink
report
parent
reply
1 point

@neatchee That good to know. The original report from the group that found it said they were unaware of any patched version being released, but they had not heard from the maintainers yet. I usually check for an update once a month anyway.

permalink
report
parent
reply
2 points

@neatchee it’s a fake proof of concept https://therecord.media/fake-zero-day-7Zip

permalink
report
reply
1 point

Why do I hear specifically about vulnerabilities in compression programs so much more than in other kinds of software?

permalink
report
reply
2 points

@TootSweet@lemmy.world because it’s specifically software that is about opening and processing arbitrary payloads.

permalink
report
parent
reply
0 points

@neatchee again?!

permalink
report
reply
1 point

@arichtman@eigenmagic.net nah, this is the one from last month, but since 7z doesn’t self-update I figure I’d do my part in getting people to grab the latest version

permalink
report
parent
reply
0 points

@arichtman @neatchee no. This was proven to be false. there’s a whole conversation about it on Mastodon. https://infosec.exchange/@obivan/113741898038858268

permalink
report
parent
reply
0 points

@screaminggoat @arichtman ah interesting. I’ll update the link to point at the actual CVE

permalink
report
parent
reply
1 point

@neatchee oh this is the one from last month. My mistake. That one is legit: CVE-2024-11477 (7.8 high)

There was some controversy this morning when someone dropped an alleged zero-day poc exploit.

permalink
report
parent
reply

Cybersecurity

!cybersecurity@fedia.io

Create post

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Rules

Community Rules

  • Be kind
  • Limit promotional activities
  • Non-cybersecurity posts should be redirected to other communities within infosec.pub.

Community stats

  • 863

    Monthly active users

  • 63

    Posts

  • 173

    Comments