CVE-2022-44900

Publication date 6 December 2022

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

9.1 · Critical

Score breakdown

Description

A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to write arbitrary files via extracting a crafted 7z file.

Status

Package Ubuntu Release Status
py7zr 24.04 LTS noble
Not affected
23.10 mantic Ignored end of life, was needs-triage
23.04 lunar Ignored end of life, was needs-triage
22.10 kinetic Ignored end of life, was needs-triage
22.04 LTS jammy
Fixed 0.11.3+dfsg-4ubuntu0.1
20.04 LTS focal Not in release
18.04 LTS bionic Not in release
16.04 LTS xenial Not in release
14.04 LTS trusty Not in release

Severity score breakdown

CVSS version: CVSS v3.0

Base score 9.1 · Critical

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

References

Related Ubuntu Security Notices (USN)

    • USN-7030-1
    • py7zr vulnerability
    • 24 September 2024

Other references


Access our resources on patching vulnerabilities