Advisory Details

November 21st, 2024

7-Zip Qcow Handler Infinite Loop Denial-of-Service Vulnerability

ZDI-24-1606
ZDI-CAN-24307

CVE ID CVE-2024-11612
CVSS SCORE 6.5, AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
AFFECTED VENDORS 7-Zip
AFFECTED PRODUCTS 7-Zip
VULNERABILITY DETAILS

This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of 7-Zip. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.

The specific flaw exists within the processing of streams. The issue results from a logic error that can lead to an infinite loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.

ADDITIONAL DETAILS

Fixed in 7-Zip 24.08


DISCLOSURE TIMELINE
  • 2024-06-26 - Vulnerability reported to vendor
  • 2024-11-21 - Coordinated public release of advisory
  • 2024-11-26 - Advisory Updated
CREDIT 2ourc3
BACK TO ADVISORIES