{"id":259567,"date":"2018-05-10T09:47:54","date_gmt":"2018-05-10T07:47:54","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=259567"},"modified":"2018-05-10T09:50:22","modified_gmt":"2018-05-10T07:50:22","slug":"critical-security-bug-found-in-7-zip","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/259567-critical-security-bug-found-in-7-zip.html","title":{"rendered":"Critical security bug found in 7-Zip"},"content":{"rendered":"<p>7-Zip has released a <strong><a href=\"https:\/\/sourceforge.net\/p\/sevenzip\/discussion\/45797\/thread\/adc65bfa\/\" target=\"_blank\" rel=\"noopener\">patch<\/a><\/strong> for a critical security bug (<a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=2018-10115\" target=\"_blank\" rel=\"nofollow noopener\"><strong>CVE-2018-10115<\/strong><\/a>) in the code which allows it to handle RAR files, <strong><a href=\"https:\/\/nakedsecurity.sophos.com\/2018\/05\/09\/critical-bug-in-7-zip-make-sure-youre-up-to-date\/\" target=\"_blank\" rel=\"noopener\">Sophos reported<\/a><\/strong>.<\/p>\n<p>The security researcher who found the bug, and developed a working exploit for it, has subsequently <strong><a href=\"https:\/\/landave.io\/2018\/05\/7-zip-from-uninitialized-memory-to-remote-code-execution\/\" target=\"_blank\" rel=\"noopener\">published<\/a><\/strong> his findings.<\/p>\n<p>According to the researcher, there were several uninitialised variables in the UnRAR code, as used by 7-Zip, making it possible to create a RAR archive file that would cause 7-Zip to execute malicious code hidden in the data part of the file.<\/p>\n<p>Building a working exploit was easier than it could have been, as 7-Zip was made without support for\u00a0address space layout randomisation (ASLR).<\/p>\n<p>This means\u00a07-Zip tools would always load into the same memory addresses, making it simpler for attackers to\u00a0predict where certain fragments of executable code would be loaded.<\/p>\n<p>7-Zip has patched the uninitialised variable vulnerability and enabled ASLR. The fixes are available from\u00a0<strong><a href=\"https:\/\/sourceforge.net\/p\/sevenzip\/discussion\/45797\/thread\/adc65bfa\/\" rel=\"nofollow\">7-Zip version 18.05<\/a><\/strong>.<\/p>\n<h3 class=\"my-4\">Now read:\u00a0<a href=\"https:\/\/mybroadband.co.za\/news\/security\/255213-update-for-ubuntu-16-04-lts-patches-security-vulnerabilities.html\">Update for Ubuntu 16.04 LTS patches security vulnerabilities<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>7-Zip has released a patch for a critical security bug.<\/p>\n","protected":false},"author":23,"featured_media":259579,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[50679,765],"class_list":["post-259567","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-7-zip","tag-sophos"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/259567"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=259567"}],"version-history":[{"count":2,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/259567\/revisions"}],"predecessor-version":[{"id":259595,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/259567\/revisions\/259595"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/259579"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=259567"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=259567"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=259567"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}