Debian Package Tracker
Register | Log in
Subscribe

py7zr

pure Python 7-zip library

Choose email to subscribe with

general
  • source: py7zr (main)
  • version: 1.1.3+dfsg-1
  • maintainer: Debian Python Team (DMD)
  • uploaders: YOKOTA Hiroshi [DMD] [DM]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 0.11.3+dfsg-1+deb11u1
  • o-o-sec: 0.11.3+dfsg-1+deb11u1
  • oldstable: 0.11.3+dfsg-5
  • stable: 0.22.0+dfsg-1
  • stable-bpo: 1.0.0+dfsg1-3~bpo13+1
  • testing: 1.1.3+dfsg-1
  • unstable: 1.1.3+dfsg-1
versioned links
  • 0.11.3+dfsg-1+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.11.3+dfsg-5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.22.0+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.0.0+dfsg1-3~bpo13+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.1.3+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python3-py7zr
action needed
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2026-23879: py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below contain an an arbitrary file write vulnerability, which allows symbolic links to be recreated outside the destination directory via crafted malicious symbolic link chains. When using extractall to extract an archive, the library restores these symbolic links, linking them to arbitrary directories on the host file system. During extraction, the program only checks the link arcname within the destination directory, but ignores the combined symlink path resolution. Attackers can exploit this vulnerability by constructing malicious archives, thereby bypassing the directory boundary restrictions implemented by the extractor. Subsequent extraction of regular files through these symbolic links can result in arbitrary file writes. This vulnerability may lead to remote code execution, privilege escalation, data corruption, or denial of service. This issue has been fixed in version 1.1.3.
Created: 2026-06-26 Last update: 2026-06-26 13:32
1 security issue in bullseye high

There is 1 open security issue in bullseye.

1 important issue:
  • CVE-2026-23879: py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below contain an an arbitrary file write vulnerability, which allows symbolic links to be recreated outside the destination directory via crafted malicious symbolic link chains. When using extractall to extract an archive, the library restores these symbolic links, linking them to arbitrary directories on the host file system. During extraction, the program only checks the link arcname within the destination directory, but ignores the combined symlink path resolution. Attackers can exploit this vulnerability by constructing malicious archives, thereby bypassing the directory boundary restrictions implemented by the extractor. Subsequent extraction of regular files through these symbolic links can result in arbitrary file writes. This vulnerability may lead to remote code execution, privilege escalation, data corruption, or denial of service. This issue has been fixed in version 1.1.3.
Created: 2026-06-26 Last update: 2026-06-26 13:32
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2026-23879: py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below contain an an arbitrary file write vulnerability, which allows symbolic links to be recreated outside the destination directory via crafted malicious symbolic link chains. When using extractall to extract an archive, the library restores these symbolic links, linking them to arbitrary directories on the host file system. During extraction, the program only checks the link arcname within the destination directory, but ignores the combined symlink path resolution. Attackers can exploit this vulnerability by constructing malicious archives, thereby bypassing the directory boundary restrictions implemented by the extractor. Subsequent extraction of regular files through these symbolic links can result in arbitrary file writes. This vulnerability may lead to remote code execution, privilege escalation, data corruption, or denial of service. This issue has been fixed in version 1.1.3.
Created: 2026-06-26 Last update: 2026-06-26 13:32
debian/patches: 2 patches to forward upstream low

Among the 3 debian patches available in version 1.1.3+dfsg-1 of the package, we noticed the following issues:

  • 2 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2026-04-14 Last update: 2026-06-21 07:30
news
[rss feed]
  • [2026-06-24] py7zr 1.1.3+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-20] Accepted py7zr 1.1.3+dfsg-1 (source) into unstable (YOKOTA Hiroshi)
  • [2026-05-29] py7zr 1.1.2-1+really1.1.0+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2026-05-24] Accepted py7zr 1.1.2-1+really1.1.0+dfsg-2 (source) into unstable (Colin Watson)
  • [2026-05-19] Accepted py7zr 1.1.2-1+really1.1.0+dfsg-1 (source) into unstable (YOKOTA Hiroshi)
  • [2026-05-18] Accepted py7zr 1.1.2+really1.1.0+dfsg-1 (source) into unstable (YOKOTA Hiroshi)
  • [2026-04-16] py7zr 1.1.2+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2026-04-13] Accepted py7zr 1.1.2+dfsg-2 (source) into unstable (YOKOTA Hiroshi)
  • [2026-02-08] py7zr 1.1.2+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-06] Accepted py7zr 1.1.2+dfsg-1 (source) into unstable (YOKOTA Hiroshi)
  • [2026-01-21] Accepted py7zr 1.1.2+dfsg-1~exp1 (source) into experimental (YOKOTA Hiroshi)
  • [2025-12-30] py7zr 1.0.0+dfsg1-5 MIGRATED to testing (Debian testing watch)
  • [2025-12-27] Accepted py7zr 1.0.0+dfsg1-5 (source) into unstable (YOKOTA Hiroshi)
  • [2025-12-26] Accepted py7zr 1.1.0+dfsg-1~exp1 (source) into experimental (YOKOTA Hiroshi)
  • [2025-11-26] py7zr 1.0.0+dfsg1-4 MIGRATED to testing (Debian testing watch)
  • [2025-11-24] Accepted py7zr 1.0.0+dfsg1-4 (source) into unstable (YOKOTA Hiroshi)
  • [2025-11-11] Accepted py7zr 1.0.0+dfsg1-3~bpo13+1 (source all) into stable-backports (Debian FTP Masters) (signed by: Nicholas D Steeves)
  • [2025-10-02] py7zr 1.0.0+dfsg1-3 MIGRATED to testing (Debian testing watch)
  • [2025-10-02] py7zr 1.0.0+dfsg1-3 MIGRATED to testing (Debian testing watch)
  • [2025-09-29] Accepted py7zr 1.0.0+dfsg1-3 (source) into unstable (YOKOTA Hiroshi)
  • [2025-08-26] py7zr 1.0.0+dfsg1-2 MIGRATED to testing (Debian testing watch)
  • [2025-08-23] Accepted py7zr 1.0.0+dfsg1-2 (source) into unstable (YOKOTA Hiroshi)
  • [2025-08-19] py7zr 1.0.0+dfsg1-1 MIGRATED to testing (Debian testing watch)
  • [2025-08-17] Accepted py7zr 1.0.0+dfsg1-1 (source) into unstable (YOKOTA Hiroshi) (signed by: Jeroen Ploemen)
  • [2024-08-12] py7zr 0.22.0+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-08-09] Accepted py7zr 0.22.0+dfsg-1 (source) into unstable (YOKOTA Hiroshi) (signed by: Étienne Mollier)
  • [2024-07-07] py7zr 0.21.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-07-04] Accepted py7zr 0.21.1+dfsg-1 (source) into unstable (YOKOTA Hiroshi) (signed by: Yogeswaran Umasankar)
  • [2024-07-03] Accepted py7zr 0.21.0+dfsg-2 (source) into unstable (YOKOTA Hiroshi) (signed by: Agathe Porte)
  • [2024-05-24] py7zr 0.21.0+dfsg-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.1.3+dfsg-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing