CVE-2017-17969: 7-Zip

High severity, CVSS 7.8. EPSS: 4.9% chance of exploitation in the next 30 days.

Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to cause a denial of service (out-of-bounds write) or potentially execute arbitrary code via a crafted ZIP archive.

Affected products

  • 7-Zip 7-Zip: before 18.00 (fixed in 18.00)
  • 7-Zip p7zip: before 18.0 (fixed in 18.0)
  • Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only

Published 2018-01-30. Last modified 2026-06-17.