A null pointer dereference vulnerability was found in p7zip. Malformed 7z file could cause the application to crash. Upstream bug: https://sourceforge.net/p/p7zip/bugs/185/
Created p7zip tracking bugs for this issue: Affects: fedora-all [bug 1394794] Affects: epel-all [bug 1394795]
p7zip 16.02 + more CVE-2016-9296.patch [1] = p7zip 16.02-2 [1] https://src.fedoraproject.org/cgit/rpms/p7zip.git/tree/CVE-2016-9296.patch
Fixed In Version field here is meant to note fixed upstream version. Based on your comment 2, it should not note 16.02. If there is not fixed upstream version yet, it should be left blank.