New 7-Zip high-severity vulnerabilities expose systems to remote attackers — users should update to version 25 ASAP

https://www.tomshardware.com/tech-industry/cyber-security/7-zip-flaws-open-door-to-remote-code-execution

165 points · 18 comments · view on lemmy.world

18 Comments

TWeaK@lemmy.today · 28 pts · 308d (13 replies)

One of the big issues with 7-Zip is that it only really updates manually. There is literally no update functionality baked in, at least in the version I've been running.

tordenflesk@lemmy.world · 31 pts · 308d (9 replies)

There is literally no update functionality baked in

Good, that's what package managers are for.

JustEnoughDucks@feddit.nl · 14 pts · 308d (8 replies)

If only windows had package managers for the 100 million machines with 7zip out there

The_Decryptor@aussie.zone · 13 pts · 308d

winget is actually smart enough to manage stuff installed outside of it, but that still requires users to actually use winget to begin with.

tordenflesk@lemmy.world · 8 pts · 307d (3 replies)

Winget, Chocolatey, Scoop, VU, Cargo. I could go on...

JustEnoughDucks@feddit.nl · 0 pts · 307d (2 replies)

Can't you not use those unless you have admin rights on your PC which the vast majority of corporations (rightly) don't give.

tordenflesk@lemmy.world · 5 pts · 307d

Right, it's the end-users responsibility to update software in a corporate environment is it?

Scoop, by default deploys in ~\Scoop, and works in 95% of cases with a regular user.

monk@lemmy.unboiled.info · 3 pts · 307d

Then the corporations are the ones on the hook to to update it. shrug

circuscritic@lemmy.ca · 3 pts · 308d (1 reply)

Winget exists, but I believe it has to be manually setup, and manually used.

It's been a while since I used Windows in general, so my knowledge is a bit outdated/rusty.

AtariDump@lemmy.world · 2 pts · 307d

Manually triggered, yes. Manually setup, no - it’s already a part of Winblows 11.

bizarroland@lemmy.world · 1 pts · 307d

I like https://ruckzuck.tools/

It has a section for updating and then a section for exploring for new programs that's relatively sanely sorted.

veniasilente@lemmy.dbzer0.com · 1 pts · 79d (1 reply)

2026

There is literally no update functionality baked in

Wonderful

Just run apt update && apt upgrade redownload from the website and rerun the installer.

TWeaK@lemmy.today · 1 pts · 54d

I'm happy to do that, but without any update notification a new update will likely go unnoticed for some time.

Psythik@lemmy.world · 1 pts · 307d

That's why I use NanaZip instead. It's a fork of 7-Zip that has been modernized.

Kissaki@programming.dev · 23 pts · 308d (1 reply)

Patches for two high-severity ZIP parsing flaws have quietly been available since July.

If you updated at some point since July 5th you already have the update.

dditty@lemmy.dbzer0.com · 2 pts · 308d

Ah thanks, I thought I remembered there being a big vulnerability earlier this year and I updated all my machines then

Linearity@infosec.pub · 8 pts · 307d (1 reply)

Dawg why is an offline program vulnerable to internet attacks :(
I’m curious as to how this works

NocturnalEngineer@lemmy.world · 9 pts · 307d

Because said offline program is used to open malicious archive files from the internet.