CVE-2018-5996: 7-Zip
High severity, CVSS 7.8. EPSS: 2.9% chance of exploitation in the next 30 days.
Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory corruptions within the PPMd code, allows remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.
Affected products
- 7-Zip 7-Zip: before 18.00 (fixed in 18.00)
- 7-Zip p7zip: before 18.0 (fixed in 18.0)
- Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
Published 2018-01-31. Last modified 2026-06-17.