
Cloud Vulnerability DB
A community-led vulnerabilities database
7-Zip version 22.01 contains a vulnerability where it fails to report errors when processing certain invalid xz files, specifically involving stream flags and reserved bits. The vulnerability was assigned CVE-2022-47112 and was later addressed in subsequent versions (CVE Details, MITRE CVE).
The vulnerability is classified as CWE-754 (Improper Check for Unusual or Exceptional Conditions). According to the CVSS 3.1 scoring system, it has been assigned a base score of 2.5 (LOW) with the following vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N. The issue specifically relates to the software's failure to properly validate and report errors when processing xz files with invalid stream flags and reserved bits (NVD Database).
When processing corrupted xz files, 7-Zip returns an OK status instead of reporting the error, which could lead to silent failures in critical tasks. This behavior violates the specification which requires error indication when reserved bits are set. The impact is particularly concerning in scenarios where programs rely on 7-Zip to handle compressed components, as the actual errors remain undetected (GitHub POC).
The vulnerability affects 7-Zip version 22.01, and some later versions are reported to be unaffected. Users are advised to upgrade to a newer version of 7-Zip that has addressed this issue (CVE Details).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."