New Update 7-Zip 16

Status
Not open for further replies.

BoraMurdar

Community Manager
Thread author
Verified
Staff Member
Well-known
Aug 30, 2012
6,598
7-Zip 16.00 was released.

7-Zip for 32-bit Windows:
http://7-zip.org/a/7z1600.exe or http://7-zip.org/a/7z1600.msi

7-Zip for 64-bit Windows x64:
http://7-zip.org/a/7z1600-x64.exe or http://7-zip.org/a/7z1600-x64.msi

What's new after 7-Zip 15.14:
  • 7-Zip now can extract multivolume ZIP archives (z01, z02, ... , zip).
  • Some bugs were fixed.

7-Zip is open source software. Most of the source code is under the GNU LGPL license. The unRAR code is under a mixed license: GNU LGPL + unRAR restrictions. Check license information here: 7-Zip license.

You can use 7-Zip on any computer, including a computer in a commercial organization. You don't need to register or pay for 7-Zip.

The main features of 7-Zip
  • High compression ratio in 7z format with LZMA and LZMA2 compression
  • Supported formats:
    • Packing / unpacking: 7z, XZ, BZIP2, GZIP, TAR, ZIP and WIM
    • Unpacking only: AR, ARJ, CAB, CHM, CPIO, CramFS, DMG, EXT, FAT, GPT, HFS, IHEX, ISO, LZH, LZMA, MBR, MSI, NSIS, NTFS, QCOW2, RAR, RPM, SquashFS, UDF, UEFI, VDI, VHD, VMDK, WIM, XAR and Z.
  • For ZIP and GZIP formats, 7-Zip provides a compression ratio that is 2-10 % better than the ratio provided by PKZip and WinZip
  • Strong AES-256 encryption in 7z and ZIP formats
  • Self-extracting capability for 7z format
  • Integration with Windows Shell
  • Powerful File Manager
  • Powerful command line version
  • Plugin for FAR Manager
  • Localizations for 87 languages
7-Zip works in Windows 10 / 8 / 7 / Vista / XP / 2012 / 2008 / 2003 / 2000 / NT. There is a port of the command line version to Linux/Unix.

On 7-Zip's SourceForge Page you can find a forum, bug reports, and feature request systems.
 
A

Alkajak

The 7-Zip project released version 16.0 of their extremely popular open-source (de)compression software, which contains critical security fixes for two issues discovered by Cisco's Talos team.

The issues are a heap overflow vulnerability (CVE-2016-2334) and an out-of-bounds read vulnerability (CVE-2016-2335). The most dangerous of these two is the latter, which Cisco says it can allow attackers to execute code on the user's machine and take over his device.

According to Cisco, the problem lies in how the 7-Zip client handles UDF files. The UDF (Universal Disk Format) file format is the official file system for DVD-Video and DVD-Audio.

The exploitation scenario is also very trivial, requiring an attacker to create a booby-trapped 7-Zip archive that contains a malicious file.

The only condition is that the user must unzip the file with a vulnerable 7-Zip version, which at this point is all of them except 16.0, the latest one.

Users may be vulnerable through third-party apps
"These type of vulnerabilities are especially concerning since vendors may not be aware they are using the affected libraries," Cisco wrote yesterday. "This can be of particular concern, for example, when it comes to security devices or antivirus products. 7-Zip is supported on all major platforms, and is one of the most popular archive utilities in-use today."

Among the products in which 7-Zip, or some of its libraries, are implemented are many antivirus applications and even some Linux distributions, where the 7-Zip command-line utility is included as a standard package.

Antivirus packages use 7-Zip to automatically unzip files in order to analyze and scan their content. Since antivirus software is also configured to scan each new file written to disk, an attacker only has to land a malicious archive on a target's device. This means that even if users update their local 7-Zip package, they may still be vulnerable.

7-Zip 16.0 Released to Fix Gaping Security Hole
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top