- Aug 17, 2014
- 11,256
Contains the latest version a fix for vulnerability CVE-2022-29072?
GitHub - kagancapar/CVE-2022-29072: 7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area.
7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area. - kagancapar/CVE-2022-29072github.com
I am sorry for being very late to reply, but today, I found some info about your question, looks like no fix included yet in latest version 22.00
The source article below sounds harsh... I don't know what is true or partially true
- CVE-2022-29072 not fixed yet
Boycott 7-zip: "Limited" Open Source & Security Issues
"Limited" Open Source 7-zip developed by Igor Pavlov, first release happened in far 1999. Licensed under LGPL-2.1-or-later, but one detail: you can't find the actual sources on Github, Gitlab, nor any public code hosting, only src.7z on official Sourceforge page. No history, no committers, no...
nixsanctuary.com
About that misguided call for a 7-Zip boycott
It's good to highlight some alternatives, but security issues are overblown
www.theregister.com