CVE-2015-1038: 7-Zip p7zip

Medium severity, CVSS 5.8. EPSS: 3.3% chance of exploitation in the next 30 days.

p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink attack in an archive.

Affected products

  • 7-Zip p7zip: version 9.20.1 only
  • Fedoraproject Fedora: version 22 only; version 23 only
  • Oracle Solaris: version 10.0 only; version 11.2 only

Published 2015-01-21. Last modified 2026-06-17.