My Lemmy Oracle
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
neatchee@urusai.social to Cybersecurity@fedia.io · 8 个月前

🚨 SECURITY PSA - 7ZIP VULN🚨

message-square
message-square
9
fedilink
2
message-square

🚨 SECURITY PSA - 7ZIP VULN🚨

neatchee@urusai.social to Cybersecurity@fedia.io · 8 个月前
message-square
9
fedilink

🚨 SECURITY PSA - 7ZIP VULN🚨

Update your 7zip, folks

https://cybersecuritynews.com/7-zip-vulnerability-arbitrary-code/

#cybersecurity #zeroday #7zip #malware #security #it #infosec

alert-triangle
You must log in or register to comment.
  • Not Simon 🐐@infosec.exchange
    link
    fedilink
    arrow-up
    2
    ·
    8 个月前

    @neatchee it’s a fake proof of concept https://therecord.media/fake-zero-day-7Zip

  • CC_FL_IT_GUY@phpc.social
    link
    fedilink
    arrow-up
    2
    ·
    8 个月前

    @neatchee
    If you read the write up, it sounds like the 7-Zip maintainers have not released a version yet with a patch. Current release is 24.09… watch for something newer.

    • neatchee@urusai.socialOP
      link
      fedilink
      arrow-up
      1
      ·
      8 个月前

      @[email protected] CVE indicates 24.08 was the patched version

      • CC_FL_IT_GUY@phpc.social
        link
        fedilink
        arrow-up
        1
        ·
        8 个月前

        @neatchee That good to know. The original report from the group that found it said they were unaware of any patched version being released, but they had not heard from the maintainers yet. I usually check for an update once a month anyway.

  • Nazo@urusai.social
    link
    fedilink
    arrow-up
    2
    ·
    8 个月前

    @neatchee Thanks for the warning. I make a lot of use of 7-Zip.

    Zstandard is used in a lot of things. This could be problematic as a whole.

    • neatchee@urusai.socialOP
      link
      fedilink
      arrow-up
      1
      ·
      8 个月前

      @[email protected] supply chain attacks are the favorite these days :/

      • Nazo@urusai.social
        link
        fedilink
        arrow-up
        1
        ·
        8 个月前

        @neatchee Sadly an all too accurate statement.

        Luckily the version of 7-Zip with the fix was back in August, so I’m guessing this CVE has been well known across most things. Each of my Linux systems were probably ok by the time I installed the current versions even (let alone updates.)

        I did need to update the Windows partition though. Haven’t booted it in ages, much less updated 7-Zip…

  • TootSweet@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    8 个月前

    Why do I hear specifically about vulnerabilities in compression programs so much more than in other kinds of software?

    • neatchee@urusai.socialOP
      link
      fedilink
      arrow-up
      2
      ·
      8 个月前

      @[email protected] because it’s specifically software that is about opening and processing arbitrary payloads.

Cybersecurity@fedia.io

cybersecurity@fedia.io

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Rules

Community Rules

  • Be kind
  • Limit promotional activities
  • Non-cybersecurity posts should be redirected to other communities within infosec.pub.
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 2 users / day
  • 4 users / week
  • 163 users / month
  • 1.16K users / 6 months
  • 1 local subscriber
  • 1 subscriber
  • 1.58K Posts
  • 901 Comments
  • Modlog
  • mods:
  • shellsharks@fedia.io
  • tweedge@fedia.io
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org