#1350 Major Security issue- loss of file-name encryption on updation of 7z archive

open
nobody
None
9
2013-07-22
2013-02-15
AmarJiith
No

Please fix this bug or at least provide a warning dialogue to users about this bug. It is a major security issue. Exact bug report: When a 7zip archive with password encryption including the encryption of file names is updated, the file name encryption ceases to exist henceforth. Though the file encryption still exists thus preventing 3rd parties from reading the documents or extracting it, it is still a problem as they become aware of the contents by reading the names of the files in it. Also, 7zip provides no warning of any sort that this would happen on updating an archive with file name encryption, thus making many people fall prey.

Discussion

  • merlin

    merlin - 2013-02-17

    Another way to reproduce the error:
    1. Create password-encrypted archive with file name encryption.
    2. Drag-and-drop a new file to the archive.

    Result: file name encryption has gone.

     
    Last edit: merlin 2013-02-17
  • jorel009

    jorel009 - 2013-07-22

    Ok this is a deal breaker from a security stand point. i cant believe this is not fixed yet. i am going to have to look at other solutions.

     

Log in to post a comment.

Get latest updates about Open Source Projects, Conferences and News.

Sign up for the SourceForge newsletter:

JavaScript is required for this form.





No, thanks