With the new 7zip exploit arent we also at risk?

Feel free to talk about anything and everything in this board.
Post Reply
ceroz
Newbie
Newbie
Posts: 2
Joined: May 14th, 2016, 11:55 am

With the new 7zip exploit arent we also at risk?

Post by ceroz »

Since Sabnzbd uses the command line version of 7zip for 7zip support arent we also at risk because of this vulnerability? Couldn't an attacker upload a 7zip archive with the exploit and post it as a tv episode causing sickbeard/sonarr users to automatically download it then trigger off the 7zip extraction?
User avatar
shypike
Administrator
Administrator
Posts: 19774
Joined: January 18th, 2008, 12:49 pm

Re: With the new 7zip exploit arent we also at risk?

Post by shypike »

You mean this report?
http://blog.talosintel.com/2016/05/mult ... ities.html

We'll upgrade the next release to the latest 7zip binaries.
Linux users should update outside of SABnzbd.
ceroz
Newbie
Newbie
Posts: 2
Joined: May 14th, 2016, 11:55 am

Re: With the new 7zip exploit arent we also at risk?

Post by ceroz »

yes, thank you :)
User avatar
shypike
Administrator
Administrator
Posts: 19774
Joined: January 18th, 2008, 12:49 pm

Re: With the new 7zip exploit arent we also at risk?

Post by shypike »

Looking at the description, it seems to be about HDF/UDF support.
SABnzbd will only send .7z files to 7zip.
For OSX there's no updated 7zip anyway.

Version 9.20 (which we include) does not contain the HFS issue.
It does contain the UDF issue, but if we add the parameter -t7z
the 7zip tool will refuse to process any .7z file which isn't in 7ZIP format.
This means that an attacker can rename a dangerous .udf file to .7z,
but then 7zip will refuse to process it.

This should be enough to cover the problem for now.
Post Reply