7-Zip Zero-Day Exploit Allegedly Leaked Online (cybersecuritynews.com)
from kid@sh.itjust.works to cybersecurity@sh.itjust.works on 30 Dec 19:08
https://sh.itjust.works/post/30316206

#cybersecurity

threaded - newest

themelm@sh.itjust.works on 30 Dec 19:55 collapse

The dev appears to think this is a fake exploit generated by LLM/AI

sourceforge.net/p/sevenzip/bugs/2539/

wizardbeard@lemmy.dbzer0.com on 30 Dec 22:12 collapse

Based off a small technicality with one of the comments in the code. The “function” referenced is actually a macro.

HackerJoe@sh.itjust.works on 01 Jan 22:12 collapse

It’s nonsense:

xcancel.com/Seifreed/status/1874245336291488179

The LZMA implementation already validates bounds elsewhere (bufLimit). If p->buf exceeds its limit, the program aborts the decompression safely.
🚫 The claim of unchecked memory access is baseless.