漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
GHSL-2026-122 7-Zip Ar SYMDEF OOB Read
Vulnerability Description
7-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain a heap out-of-bounds read in 7-Zip Ar handler BSD SYMDEF parser. A 4-byte heap out-of-bounds read exists in the Unix ar archive parser in 7-Zip. When parsing a BSD-style __.SYMDEF symbol table, the ParseLibSymbols function reads a 32-bit namesSize field via Get32 at a position that can equal the buffer size, reading 4 bytes past the end of the heap allocation. This reads uninitialized heap data under the default allocator. Version 26.01 patches the issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Vulnerability Type
整数溢出或超界折返
Vulnerability Title
7-Zip 输入验证错误漏洞
Vulnerability Description
7-Zip是7-Zip开源的一个压缩软件。 7-Zip 9.18版本至26.00版本存在输入验证错误漏洞,该漏洞源于Unix ar存档解析器的BSD SYMDEF解析器中存在堆越界读取,可能导致读取未初始化堆数据。
CVSS Information
N/A
Vulnerability Type
N/A