CVE-2025-0411
Public on 2025-01-25
Modified on 2025-01-25
Description
7-Zip Mark-of-the-Web Bypass Vulnerability
NOTE: Since p7zip/16.02+transitional.1 src:p7zip is only a empty source package
NOTE: depending on 7zip. Mark this version as fixed version.
NOTE: http://www.zerodayinitiative.com/advisories/ZDI-25-045/
NOTE: Since p7zip/16.02+transitional.1 src:p7zip is only a empty source package
NOTE: depending on 7zip. Mark this version as fixed version.
NOTE: http://www.zerodayinitiative.com/advisories/ZDI-25-045/
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
HAQM Linux 2 - Graphicsmagick1.3 Extra | p7zip | Not Affected | ||
HAQM Linux 2023 | p7zip | Not Affected |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
HAQM Linux | CVSSv3 | 7.0 | CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
NVD | CVSSv3 | 7.0 | CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |