7-Zip-zstd icon indicating copy to clipboard operation
7-Zip-zstd copied to clipboard

Please release 23.01 to fix security vulnerability

Open Hermholtz opened this issue 2 years ago • 13 comments
trafficstars

Hey,

7-zip is also vulnerable - https://www.zerodayinitiative.com/advisories/ZDI-23-1164/

It's been patched in 23.00 and the newest version is 23.01. Can you please update and release it?

Thank you in advance!

Hermholtz avatar Sep 01 '23 11:09 Hermholtz

any progress ?

dsm avatar Sep 08 '23 11:09 dsm

+1

Dark-Noir avatar Sep 14 '23 16:09 Dark-Noir

+1

lijianwei2019 avatar Sep 29 '23 15:09 lijianwei2019

Note that this issue is duplicated! See #337. Maybe closing this issue and replying under the previous issue is better.

RocketMaDev avatar Oct 04 '23 16:10 RocketMaDev

Dear Mr @mcmilk please find time to release the new version. You might also publish the step by step instruction on how to built it, maybe somebody would be able to take over/help you. Thanks in advance!

Hermholtz avatar Oct 30 '23 08:10 Hermholtz

Dev, Please update to new version

truefriend-cz avatar Dec 23 '23 13:12 truefriend-cz

+1

whytf avatar Jan 05 '24 15:01 whytf

Might want to check out NanaZip (v3 preview 0 version) as an alternative since the dev of this project is short on time.

redactedscribe avatar Jan 28 '24 18:01 redactedscribe

Might want to check out NanaZip as an alternative since the dev of this project is short on time.

NanaZip is older public date than this and in version Preview. And NanaZip does not contain build as MSI or EXE installer.

truefriend-cz avatar Jan 28 '24 18:01 truefriend-cz

@truefriend-cz thank you for the recommendation. Trying.

Hermholtz avatar Jan 28 '24 19:01 Hermholtz

NanaZip is older public date than this and in version Preview. And NanaZip does not contain build as MSI or EXE installer.

The v3 preview 0 version is using 7-Zip 23.01.

redactedscribe avatar Jan 28 '24 19:01 redactedscribe

@redactedscribe Thank you for finding NanaZip. So far so good. Only CLI in NanaZip is a bit of an unknown for me, but I opened an issue, we'll see how it goes.

Hermholtz avatar Jan 28 '24 19:01 Hermholtz

Dear @mcmilk , the new version of 7-zip has appeared. Please update the fine fork of you. Thank you.

https://sourceforge.net/p/sevenzip/discussion/45797/thread/b92679e642/

Hermholtz avatar May 16 '24 02:05 Hermholtz

See #377 with 24.07

stefano2734 avatar Jul 13 '24 11:07 stefano2734

I've stopped using this fork as it is against common sense to use software with security vulnerabilities. I've reverted to plain 7-Zip, will consider other forks, such as NanaZip. Therefore closing this.

Hermholtz avatar Jul 13 '24 14:07 Hermholtz