CVE-2017-17969: 7-Zip
High severity, CVSS 7.8. EPSS: 4.9% chance of exploitation in the next 30 days.
Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to cause a denial of service (out-of-bounds write) or potentially execute arbitrary code via a crafted ZIP archive.
Affected products
- 7-Zip 7-Zip: before 18.00 (fixed in 18.00)
- 7-Zip p7zip: before 18.0 (fixed in 18.0)
- Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
Published 2018-01-30. Last modified 2026-06-17.