Comment on Wide-ranging 7-zip vulnerability with 8.8 CVE rating allows for code execution — hundreds of millions of machines potentially at risk

quick_snail@feddit.nl ⁨3⁩ ⁨days⁩ ago

That actually doesn’t seem to be so severe.

How many people download some random archive and then, after extracting it, they double click on the files inside it?

It says the risk of this vuln is arbitrary code execution of a maliciously crafted archive.

After fixing this bug, most 7zip users will still be vulnerable to arbitrary code execution due to maliciously crafted archives.

source
Sort:hotnewtop