Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Chocolatey is shipped with a vulnerable 7zip #1556

Closed
Skons opened this issue May 2, 2018 · 11 comments
Closed

Chocolatey is shipped with a vulnerable 7zip #1556

Skons opened this issue May 2, 2018 · 11 comments

Comments

@Skons
Copy link

Skons commented May 2, 2018

Chocolatey is shipped with 7zip version 18.1.0.0 which allowes remote code execution. While i doubt it is easily abused in the context of chocolatey or the choco packages, users that do not have full blown execution rights on a machine could abuse this vulnerable 7zip executable. Can a new choco version be published with an updated 7zip version?

https://landave.io/2018/05/7-zip-from-uninitialized-memory-to-remote-code-execution/

image

@ferventcoder
Copy link
Member

@Skons you understand responsible security reporting right?

@ferventcoder
Copy link
Member

Just because Chocolatey is open source, you should probably let us know privately so we can fix the issue - especially since it was just announced like yesterday.

@ferventcoder
Copy link
Member

https://chocolatey.org/security for next time. Please follow proper procedures for something like this.

@Skons
Copy link
Author

Skons commented May 2, 2018

I'm totally sorry for this, i thought i was doing this the right way.

@ferventcoder
Copy link
Member

No worries - security issues are sensitive. That's why that article had dates listed for when they found the vulnerability, let the vendor know and all of that before it became public.

https://landave.io/2018/05/7-zip-from-uninitialized-memory-to-remote-code-execution/#timeline-of-disclosure :

Timeline of Disclosure
2018-03-06 - Discovery
2018-03-06 - Report
2018-04-14 - MITRE assigned CVE-2018-10115
2018-04-30 - 7-Zip 18.05 released, fixing CVE-2018-10115 and enabling ASLR on the executables.

@ferventcoder
Copy link
Member

@Skons it's no worries, and it did point out a gap in issue reporting process. Now we have it in the issue template to help folks down the right path.
image

We'll get this fixed and pushed out soon.

@ferventcoder
Copy link
Member

"This" being fixing the vulnerability.

@ferventcoder
Copy link
Member

Duplicate of #1557

@ferventcoder ferventcoder marked this as a duplicate of #1557 May 3, 2018
@ferventcoder
Copy link
Member

I know this sounds weird to have a duplicate in a newer issue, but @gep13 must have thought this was on the chocolatey.org repo and created the new issue to point to as part of his pull request. 😄

@gep13
Copy link
Member

gep13 commented May 4, 2018

@ferventcoder yeah, I had a bit of a noob moment, where I forgot about this issue when I was working through the process of doing the actual update. I had already created the commit, and referenced the new issue, so I thought I would leave it and hope nobody noticed 🎉

@ferventcoder
Copy link
Member

ferventcoder commented May 4, 2018

When doing the paperwork, it always comes up ;)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants