CVE-2023-52168

Publication date 3 July 2024

Last updated 15 April 2025


Ubuntu priority

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite two bytes at multiple offsets beyond the allocated buffer size: buffer+512*i-2, for i=9, i=10, i=11, etc.

Read the notes from the security team

Status

Package Ubuntu Release Status
7zip 25.04 plucky
Not affected
24.10 oracular
Not affected
24.04 LTS noble
23.10 mantic Ignored end of life, was needs-triage
22.04 LTS jammy
20.04 LTS focal Not in release

Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

Get Ubuntu Pro

Notes


john-breton

Sourceforge is private for the 7-Zip project, but the linked disclosure blog includes the patched code.

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
7zip