Unzip Project Unzip version 6.0 : Security vulnerabilities, CVEs (2024)

cpe:2.3:a:unzip_project:unzip:6.0:*:*:*:*:*:*:*

Copy

CVE-2022-0530

A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

Source: Red Hat, Inc.

Max CVSS

5.5

EPSS Score

0.18%

Published

2022-02-09

Updated

2023-11-09

CVE-2022-0529

A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

Source: Red Hat, Inc.

CVE-2021-4217

A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

Source: Red Hat, Inc.

Max CVSS

3.3

EPSS Score

0.08%

Published

2022-08-24

Updated

2022-11-29

CVE-2019-13232

Info-ZIP UnZip 6.0 mishandles the overlapping of files inside a ZIP container, leading to denial of service (resource consumption), aka a "better zip bomb" issue.

Source: MITRE

Max CVSS

3.3

EPSS Score

0.08%

Published

2019-07-04

Updated

2020-06-16

CVE-2018-1000035

A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a denial of service or to possibly achieve code execution.

Source: MITRE

Max CVSS

7.8

EPSS Score

1.19%

Published

2018-02-09

Updated

2020-08-24

CVE-2018-18384

Info-ZIP UnZip 6.0 has a buffer overflow in list.c, when a ZIP archive has a crafted relationship between the compressed-size value and the uncompressed-size value, because a buffer size is 10 and is supposed to be 12.

Source: MITRE

Max CVSS

5.5

Published

2018-10-16

Updated

2019-12-16

CVE-2016-9844

Buffer overflow in the zi_short function in zipinfo.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via a large compression method value in the central directory file header.

Source: MITRE

Max CVSS

4.0

EPSS Score

0.70%

Published

2017-01-18

Updated

2019-12-16

CVE-2015-7697

Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (infinite loop) via empty bzip2 data in a ZIP archive.

Source: MITRE

Max CVSS

4.3

EPSS Score

4.41%

Published

2015-11-06

Updated

2019-12-16

CVE-2015-7696

Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly execute arbitrary code via a crafted password-protected ZIP archive, possibly related to an Extra-Field size value.

Source: MITRE

Max CVSS

6.8

EPSS Score

4.69%

Published

2015-11-06

Updated

2019-12-16

CVE-2014-9913

Buffer overflow in the list_files function in list.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via vectors related to the compression method.

Source: MITRE

Max CVSS

4.0

EPSS Score

0.84%

Published

2017-01-18

Updated

2019-12-16

CVE-2014-9636

unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra field with an uncompressed size smaller than the compressed field size in a zip archive that advertises STORED method compression.

Source: MITRE

Max CVSS

5.0

EPSS Score

26.01%

Published

2015-02-06

Updated

2019-12-16

CVE-2014-8141

Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

Source: Red Hat, Inc.

Max CVSS

7.8

EPSS Score

0.65%

Published

2020-01-31

Updated

2023-02-13

CVE-2014-8140

Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

Source: Red Hat, Inc.

Max CVSS

7.8

EPSS Score

0.65%

Published

2020-01-31

Updated

2023-02-13

CVE-2014-8139

Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

Source: Red Hat, Inc.

Max CVSS

7.8

EPSS Score

0.65%

Published

2020-01-31

Updated

2023-02-13

Unzip Project Unzip version 6.0 : Security vulnerabilities, CVEs (2024)
Top Articles
Realogy changes name to Anywhere Real Estate
Tradelines – Make Money with Credit Cards – Simple Passive Cashfow
Spectrum Gdvr-2007
Kmart near me - Perth, WA
Main Moon Ilion Menu
Www.fresno.courts.ca.gov
Www.craigslist Virginia
Quick Pickling 101
Frank Lloyd Wright, born 150 years ago, still fascinates
Es.cvs.com/Otchs/Devoted
Khatrimaza Movies
Craigslist Dog Sitter
DIN 41612 - FCI - PDF Catalogs | Technical Documentation
Bros Movie Wiki
Aktuelle Fahrzeuge von Autohaus Schlögl GmbH & Co. KG in Traunreut
The ULTIMATE 2023 Sedona Vortex Guide
Cvs Appointment For Booster Shot
Troy Bilt Mower Carburetor Diagram
Kiddle Encyclopedia
Sulfur - Element information, properties and uses
Apple Original Films and Skydance Animation’s highly anticipated “Luck” to premiere globally on Apple TV+ on Friday, August 5
Craigslist Northfield Vt
R. Kelly Net Worth 2024: The King Of R&B's Rise And Fall
Academy Sports Meridian Ms
Olivia Maeday
Bay Area Craigslist Cars For Sale By Owner
Evil Dead Rise Ending Explained
Xxn Abbreviation List 2023
Obituaries, 2001 | El Paso County, TXGenWeb
Craftsman Yt3000 Oil Capacity
Busch Gardens Wait Times
Bi State Schedule
Exploring TrippleThePotatoes: A Popular Game - Unblocked Hub
Joe's Truck Accessories Summerville South Carolina
Closest 24 Hour Walmart
Ewwwww Gif
Greater Keene Men's Softball
Los Garroberros Menu
Walgreens Agrees to Pay $106.8M to Resolve Allegations It Billed the Government for Prescriptions Never Dispensed
Uc Santa Cruz Events
How much does Painttool SAI costs?
Final Jeopardy July 25 2023
2007 Peterbilt 387 Fuse Box Diagram
Kutty Movie Net
Craigslist Food And Beverage Jobs Chicago
Lamont Mortuary Globe Az
Bustednewspaper.com Rockbridge County Va
Southwest Airlines Departures Atlanta
Catchvideo Chrome Extension
Ts In Baton Rouge
This Doctor Was Vilified After Contracting Ebola. Now He Sees History Repeating Itself With Coronavirus
Blippi Park Carlsbad
Latest Posts
Article information

Author: Domingo Moore

Last Updated:

Views: 6151

Rating: 4.2 / 5 (53 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Domingo Moore

Birthday: 1997-05-20

Address: 6485 Kohler Route, Antonioton, VT 77375-0299

Phone: +3213869077934

Job: Sales Analyst

Hobby: Kayaking, Roller skating, Cabaret, Rugby, Homebrewing, Creative writing, amateur radio

Introduction: My name is Domingo Moore, I am a attractive, gorgeous, funny, jolly, spotless, nice, fantastic person who loves writing and wants to share my knowledge and understanding with you.