CVE-2024-11612
Public on 2024-11-22
Modified on 2026-03-07
Description
7-Zip CopyCoder Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of 7-Zip. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.
The specific flaw exists within the processing of streams. The issue results from a logic error that can lead to an infinite loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-24307.
Amazon Linux is ending support for p7zip package in the GraphicsMagick1.3 extra for Amazon Linux 2. p7zip has been abandoned by its authors and is not receiving patches for new security issues. We recommend that any customers relying on it urgently migrate to 7zip on AL2023 or use it cautiously with trusted data only.
The specific flaw exists within the processing of streams. The issue results from a logic error that can lead to an infinite loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-24307.
Amazon Linux is ending support for p7zip package in the GraphicsMagick1.3 extra for Amazon Linux 2. p7zip has been abandoned by its authors and is not receiving patches for new security issues. We recommend that any customers relying on it urgently migrate to 7zip on AL2023 or use it cautiously with trusted data only.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Graphicsmagick1.3 Extra | p7zip | No Fix Planned | ||
| Amazon Linux 2023 | p7zip | No Fix Planned |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 3.3 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L |