Bug 2403091 - Two high-severity vulnerabilities CVE2025-11001 and CVE-2025-11002
Summary: Two high-severity vulnerabilities CVE2025-11001 and CVE-2025-11002
Keywords:
Status: NEW
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: p7zip
Version: epel8
Hardware: Unspecified
OS: Unspecified
unspecified
high
Target Milestone: ---
Assignee: Davide Cavalca
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-10-10 14:22 UTC by Dave B
Modified: 2025-10-10 14:22 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Dave B 2025-10-10 14:22:41 UTC
Description of problem:
Two high-severity vulnerabilities have been discovered in the popular open-source file archiver, 7-Zip, which could allow remote attackers to execute arbitrary code.

Identified as CVE-2025-11001 and CVE-2025-11002, the flaws affect all versions of the software prior to the latest release and require immediate patching.

The developer of 7-Zip has released version 25.00, which rectifies these security flaws. All users are strongly advised to update their installations immediately to protect against potential exploitation

Version-Release number of selected component (if applicable):
p7zip-plugins-16.02-31.el8


Additional info:
https://cybersecuritynews.com/7-zip-vulnerabilities/


Note You need to log in before you can comment on or make changes to this bug.