MGASA-2021-0305

Source
https://advisories.mageia.org/MGASA-2021-0305.html
Import Source
https://advisories.mageia.org/MGASA-2021-0305.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2021-0305
Upstream
  • CVE-2021-3465
Published
2021-06-30T23:58:41Z
Modified
2026-04-16T04:43:27.475948596Z
Summary
Updated p7zip package fixes security vulnerabilities
Details

In p7zip-17.03, the function NCompress::CCopyCoder::Code in CPP/7zip/Common/StreamObjects.cpp will call outStream->Write where a memcpy uses a NULL pointer as destination address, leading to a crash (CVE-2021-3465).

Null pointer dereference in function Reserve() found in p7zip 16.02 (rhbz#1951218).

Null Pointer Dereference in function NArchive::NLzh::CItem::GetUnixTime found in p7zip 16.02 (rhbz#1951224).

The p7zip package has been patched to fix these issues.

Also, the Mageia 7 package has been updated to version 17.03.

References
Credits

Affected packages

Mageia:7 / p7zip

Package

Name
p7zip
Purl
pkg:rpm/mageia/p7zip?arch=source&distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
17.03-1.1.mga7

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2021-0305.json"

Mageia:8 / p7zip

Package

Name
p7zip
Purl
pkg:rpm/mageia/p7zip?arch=source&distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
17.03-1.1.mga8

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2021-0305.json"