Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[REQ] Patch critical vulnerability in 7-zip format (CVE-2024-11477) #1553

Closed
mdaeron opened this issue Nov 27, 2024 · 2 comments
Closed

[REQ] Patch critical vulnerability in 7-zip format (CVE-2024-11477) #1553

mdaeron opened this issue Nov 27, 2024 · 2 comments

Comments

@mdaeron
Copy link

mdaeron commented Nov 27, 2024

Is your feature request related to a problem? Please describe

A potentially serious vulnerabilty in 7-zip decompression was reported recently.

Describe the solution you'd like

I would like Keka to used a patched version of 7-zip decompression. Also, ideally, users would be able to check which protocol version is used for a given format. Perhaps this is already implemented but I could not find where.

Additional context

Keka is awesome, thanks for making it!

@aonez aonez added the 7zz label Nov 27, 2024
@aonez aonez added this to the Look at milestone Nov 27, 2024
@aonez aonez added the CVE label Nov 27, 2024
@aonez
Copy link
Owner

aonez commented Nov 27, 2024

Thanks for the info @mdaeron! A few points:

  • Only 7zz has Zstandard support so only macOS 10.13 or newer can be affected
  • Keka uses zstd, not 7zz, for Zstandard files so it is not affected while using the user interface
  • Keka and it's binaries are sandboxed

That said 7-Zip 24.07 was released on 2024-06-19 and reports:
The bug was fixed: 7-Zip could crash for some incorrect ZSTD archives.

Probably this was the fix for this vulnerability that was reported on 2024-06-12 to the developer. Keka uses 24.08 version so this vulnerability should be already fixed.

Lets follow the updates about this vulnerability, but fear not :)

@aonez aonez added the macOS label Nov 27, 2024
@aonez
Copy link
Owner

aonez commented Nov 27, 2024

Just saw this on the report:

Fixed in fixed in 7-Zip 24.07

I've overlooked it before. So indeed this is already fixed. Thanks again @mdaeron!

@aonez aonez closed this as completed Nov 27, 2024
@aonez aonez added the fixed label Nov 27, 2024
@aonez aonez modified the milestones: Look at, 1.4.7, macOS-1.4.7 Nov 27, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants