Ancestors

Toot

Written by neatchee on 2024-12-30 at 22:01

🚨 SECURITY PSA - 7ZIP VULN🚨

Update your 7zip, folks

https://cybersecuritynews.com/7-zip-vulnerability-arbitrary-code/

[#]cybersecurity #zeroday #7zip #malware #security #it #infosec

=> More informations about this toot | More toots from neatchee@urusai.social

Descendants

Written by Ariel on 2024-12-30 at 22:01

@neatchee again?!

=> More informations about this toot | More toots from arichtman@eigenmagic.net

Written by Not Simon 🐐 on 2024-12-30 at 22:07

@arichtman @neatchee no. This was proven to be false. there's a whole conversation about it on Mastodon. https://infosec.exchange/@obivan/113741898038858268

=> More informations about this toot | More toots from screaminggoat@infosec.exchange

Written by neatchee on 2024-12-30 at 22:11

@screaminggoat @arichtman ah interesting. I'll update the link to point at the actual CVE

=> More informations about this toot | More toots from neatchee@urusai.social

Written by Not Simon 🐐 on 2024-12-30 at 22:14

@neatchee oh this is the one from last month. My mistake. That one is legit: CVE-2024-11477 (7.8 high)

There was some controversy this morning when someone dropped an alleged zero-day poc exploit.

=> More informations about this toot | More toots from screaminggoat@infosec.exchange

Written by neatchee on 2024-12-30 at 22:16

@screaminggoat heh yeah, that was supposedly utilizing this CVE which is what led me to it.

I would normally hold off on posting something this old but 7z has no self update mechanism so people tend to run old versions :/

=> More informations about this toot | More toots from neatchee@urusai.social

Written by neatchee on 2024-12-30 at 22:17

@arichtman nah, this is the one from last month, but since 7z doesn't self-update I figure I'd do my part in getting people to grab the latest version

=> More informations about this toot | More toots from neatchee@urusai.social

Written by Not Simon 🐐 on 2024-12-30 at 22:04

@neatchee it's a fake proof of concept https://therecord.media/fake-zero-day-7Zip

=> More informations about this toot | More toots from screaminggoat@infosec.exchange

Proxy Information
Original URL
gemini://mastogem.picasoft.net/thread/113744023657869947
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
334.38574 milliseconds
Gemini-to-HTML Time
1.385599 milliseconds

This content has been proxied by September (ba2dc).