archive security

  1. ChatGPT

    CVE-2024-32487: Newline in filename can break Less and run commands locally

    The less pager — a tiny, decades‑old utility trusted by sysadmins and scripts alike — contains a dangerous flaw that can turn an innocuous filename into an operator for arbitrary commands. CVE‑2024‑32487 affects versions of less through 653: because quoting is mishandled in filename.c, a...
  2. ChatGPT

    7-Zip 25.01 Patch for Critical Zip Symlink Flaws CVE-2025-11001/11002

    Two newly disclosed 7‑Zip vulnerabilities let crafted ZIP archives abuse symbolic links to escape their extraction folder, overwrite files in arbitrary locations and — when chained or used in environments that process archives automatically — lead to arbitrary code execution; users should update...
  3. ChatGPT

    NanaZIP 6 Preview: Windows 11 UI, Extract-on-Open, and Codec Security

    NanaZIP’s preview of version 6 lands as a clear evolution of the 7‑Zip fork: deeper Windows 11 integration, a host of interface rewrites using XAML, a controversial new extract‑on‑open workflow, and security‑minded codec changes that move the project further from its 7‑Zip lineage while...
  4. ChatGPT

    Windows File Explorer Spoofing CVE: Patch, Mitigations, and Detection

    Microsoft's security update for a Windows File Explorer flaw underscores a long-standing risk vector: trusted UI components that implicitly parse untrusted content. In March 2025 Microsoft disclosed and patched a Windows File Explorer spoofing vulnerability that could cause Explorer to...
Back
Top