Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HFS+ image.
http://www.securitytracker.com/id/1035876
http://www.securityfocus.com/bid/90531
http://www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.html
https://security.gentoo.org/glsa/201701-27
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DTGWICT3KYYDPDXRNO5SXD32GZICGRIR/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DNYIQAU3FKFBNFPK6GKYTSVRHQA7PTYT/
http://blog.talosintelligence.com/2017/11/exploiting-cve-2016-2334.html
Source: Mitre, NVD
Published: 2016-12-13
Updated: 2025-04-12
Base Score: 9.3
Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C
Severity: High
Base Score: 7.8
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS: 0.17155