{"id":11296,"date":"2018-01-30T06:30:02","date_gmt":"2018-01-30T14:30:02","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/01\/30\/news-5067\/"},"modified":"2018-01-30T06:30:02","modified_gmt":"2018-01-30T14:30:02","slug":"news-5067","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/01\/30\/news-5067\/","title":{"rendered":"Multiple vulnerabilities in 7-Zip. Get it updated now!"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.techhive.com\/images\/article\/2016\/03\/thinkstockphotos-497863290-100648027-primary.idge.jpg\"\/><\/p>\n<p><strong>Credit to Author: Woody Leonhard| Date: Tue, 30 Jan 2018 05:17:00 -0800<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">Late last year, landave, a self-described \u201cComputer Science student enjoying cryptography, reverse engineering, and other information security topics,\u201d discovered two <\/span><a href=\"https:\/\/landave.io\/2018\/01\/7-zip-multiple-memory-corruptions-via-rar-and-zip\/\" rel=\"nofollow\"><span style=\"font-weight: 400;\">startling security holes<\/span><\/a><span style=\"font-weight: 400;\"> in 7-Zip, a free zip program I\u2019ve <\/span><a href=\"https:\/\/www.computerworld.com\/article\/3199125\/microsoft-windows\/top-30-free-apps-for-windows-10.html#slide5\"><span style=\"font-weight: 400;\">recommended for years<\/span><\/a><span style=\"font-weight: 400;\">. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bottom line: If you haven\u2019t updated 7-Zip in the past few days, get off your tail and do it now.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The bugs are subtle and, as best as I can tell, have never been leveraged in the wild. But that\u2019s going to change as landave\u2019s analysis reaches the mainstream.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Details of the bugs have to do with 7-Zip memory corruption, made worse by not running ASLR and DEP, and a heap buffer overflow in the shrink routine. Landave applied for, and received, a <\/span><a href=\"https:\/\/www.cvedetails.com\/cve-help.php\" rel=\"nofollow\"><span style=\"font-weight: 400;\">MITRE number<\/span><\/a><span style=\"font-weight: 400;\"> for the latter, CVE-2017-17969.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">There\u2019s been <\/span><a href=\"https:\/\/news.ycombinator.com\/item?id=16222342\" rel=\"nofollow\"><span style=\"font-weight: 400;\">a lot of back and forth<\/span><\/a><span style=\"font-weight: 400;\"> about the bugs, but the upshot is that 7-Zip\u2019s creator, Igor Pavlov, released a new version of 7-Zip, version 18.01, on Jan. 28. That&#8217;s the version you need.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you use 7-Zip, you can see which version you\u2019re running by starting 7-Zip and clicking on Help &gt; About 7-Zip. If you have a version prior to 18.01, get the new one. Now.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Updating 7-Zip couldn\u2019t be simpler.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Step 1.<\/strong> Go to the official <\/span><a href=\"http:\/\/www.7-zip.org\/\" rel=\"nofollow\"><span style=\"font-weight: 400;\">7-Zip page<\/span><\/a><span style=\"font-weight: 400;\"> and click the link to download either the 32-bit or 64-bit version. <\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Step 2.<\/strong> Right-click on the 7z1801-x64.exe file, and choose Run as administrator. If you get a \u201cWindows protected your PC\u201d message from SmartScreen, mutter an appropriate epithet, click the link for &#8220;More information,&#8221; then click &#8220;Run anyway.&#8221;<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Step 3.<\/strong> Click yes on the User Account Control prompt, choose a destination folder, let the installer run, and reboot your computer.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">7-Zip has a lot of good features. Don\u2019t let it bite you.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Thx to <\/span><a href=\"https:\/\/borncity.com\/win\/2018\/01\/30\/7-zip-vulnerable-update-to-v18-0-1\/\" rel=\"nofollow\"><span style=\"font-weight: 400;\">G\u00fcnter Born<\/span><\/a><\/p>\n<p><span style=\"font-weight: 400;\">(P.S. Not sure where landave goes to school, but he just published a PhD-worthy dissertation.)<\/span><\/p>\n<p><i><span style=\"font-weight: 400;\">Join us for one-year birthday libations on the <\/span><\/i><a href=\"https:\/\/www.askwoody.com\/2018\/get-7-zip-updated-now\/\" rel=\"nofollow\"><i><span style=\"font-weight: 400;\">AskWoody Lounge<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">.<\/span><\/i><\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3252031\/microsoft-windows\/multiple-vulnerabilities-in-7-zip-get-it-updated-now.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.techhive.com\/images\/article\/2016\/03\/thinkstockphotos-497863290-100648027-primary.idge.jpg\"\/><\/p>\n<p><strong>Credit to Author: Woody Leonhard| Date: Tue, 30 Jan 2018 05:17:00 -0800<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p><span style=\"font-weight: 400;\">Late last year, landave, a self-described \u201cComputer Science student enjoying cryptography, reverse engineering, and other information security topics,\u201d discovered two <\/span><a href=\"https:\/\/landave.io\/2018\/01\/7-zip-multiple-memory-corruptions-via-rar-and-zip\/\" rel=\"nofollow\"><span style=\"font-weight: 400;\">startling security holes<\/span><\/a><span style=\"font-weight: 400;\"> in 7-Zip, a free zip program I\u2019ve <\/span><a href=\"https:\/\/www.computerworld.com\/article\/3199125\/microsoft-windows\/top-30-free-apps-for-windows-10.html#slide5\"><span style=\"font-weight: 400;\">recommended for years<\/span><\/a><span style=\"font-weight: 400;\">. <\/span><\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3252031\/microsoft-windows\/multiple-vulnerabilities-in-7-zip-get-it-updated-now.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[714,10761],"class_list":["post-11296","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-security","tag-windows-10"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/11296","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=11296"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/11296\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=11296"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=11296"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=11296"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}