Vulnerability CVE-2023-52168


Published: 2024-07-03

Description:
The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite two bytes at multiple offsets beyond the allocated buffer size: buffer+512*i-2, for i=9, i=10, i=11, etc.

 References:
https://sourceforge.net/p/sevenzip/bugs/2402/
https://www.openwall.com/lists/oss-security/2024/07/03/10
http://www.openwall.com/lists/oss-security/2024/07/03/10

Copyright 2026, cxsecurity.com

 

Back to Top