HTTP: 7-Zip 7Z File PPMd Properties Parsing Integer Underflow

This signature detects attempts to exploit a known vulnerability against 7-Zip. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the Application.

Extended Description

Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.

Affected Products

Netapp active_iq_unified_manager

Short Name
HTTP:STC:7-ZIP-PPMD-UNDERFLOW
Severity
Major
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
7-Zip 7Z CVE-2023-31102 File Integer PPMd Parsing Properties Underflow
Release Date
01/18/2024
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3670
False Positive
Unknown
Vendors

Netapp

Found a potential security threat?