Unzip Project Unzip version 6.0 : Security vulnerabilities, CVEs (2024)

cpe:2.3:a:unzip_project:unzip:6.0:*:*:*:*:*:*:*

Copy

CVE-2022-0530

A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

Source: Red Hat, Inc.

Max CVSS

5.5

EPSS Score

0.18%

Published

2022-02-09

Updated

2023-11-09

CVE-2022-0529

A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

Source: Red Hat, Inc.

CVE-2021-4217

A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

Source: Red Hat, Inc.

Max CVSS

3.3

EPSS Score

0.08%

Published

2022-08-24

Updated

2022-11-29

CVE-2019-13232

Info-ZIP UnZip 6.0 mishandles the overlapping of files inside a ZIP container, leading to denial of service (resource consumption), aka a "better zip bomb" issue.

Source: MITRE

Max CVSS

3.3

EPSS Score

0.08%

Published

2019-07-04

Updated

2020-06-16

CVE-2018-1000035

A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a denial of service or to possibly achieve code execution.

Source: MITRE

Max CVSS

7.8

EPSS Score

1.19%

Published

2018-02-09

Updated

2020-08-24

CVE-2018-18384

Info-ZIP UnZip 6.0 has a buffer overflow in list.c, when a ZIP archive has a crafted relationship between the compressed-size value and the uncompressed-size value, because a buffer size is 10 and is supposed to be 12.

Source: MITRE

Max CVSS

5.5

Published

2018-10-16

Updated

2019-12-16

CVE-2016-9844

Buffer overflow in the zi_short function in zipinfo.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via a large compression method value in the central directory file header.

Source: MITRE

Max CVSS

4.0

EPSS Score

0.70%

Published

2017-01-18

Updated

2019-12-16

CVE-2015-7697

Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (infinite loop) via empty bzip2 data in a ZIP archive.

Source: MITRE

Max CVSS

4.3

EPSS Score

4.41%

Published

2015-11-06

Updated

2019-12-16

CVE-2015-7696

Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly execute arbitrary code via a crafted password-protected ZIP archive, possibly related to an Extra-Field size value.

Source: MITRE

Max CVSS

6.8

EPSS Score

4.69%

Published

2015-11-06

Updated

2019-12-16

CVE-2014-9913

Buffer overflow in the list_files function in list.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via vectors related to the compression method.

Source: MITRE

Max CVSS

4.0

EPSS Score

0.84%

Published

2017-01-18

Updated

2019-12-16

CVE-2014-9636

unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra field with an uncompressed size smaller than the compressed field size in a zip archive that advertises STORED method compression.

Source: MITRE

Max CVSS

5.0

EPSS Score

26.01%

Published

2015-02-06

Updated

2019-12-16

CVE-2014-8141

Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

Source: Red Hat, Inc.

Max CVSS

7.8

EPSS Score

0.65%

Published

2020-01-31

Updated

2023-02-13

CVE-2014-8140

Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

Source: Red Hat, Inc.

Max CVSS

7.8

EPSS Score

0.65%

Published

2020-01-31

Updated

2023-02-13

CVE-2014-8139

Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

Source: Red Hat, Inc.

Max CVSS

7.8

EPSS Score

0.65%

Published

2020-01-31

Updated

2023-02-13

Unzip Project Unzip version 6.0 : Security vulnerabilities, CVEs (2024)
Top Articles
Costco Anywhere Visa® Card by Citi review: Big savings for shoppers
What Is a SIC Code, Who Needs a SIC Code, and How To Find Yours
Tattoo Shops Lansing Il
Global Foods Trading GmbH, Biebesheim a. Rhein
Caesars Rewards Loyalty Program Review [Previously Total Rewards]
No Limit Telegram Channel
Obor Guide Osrs
P2P4U Net Soccer
Mustangps.instructure
Rochester Ny Missed Connections
Mikayla Campinos Videos: A Deep Dive Into The Rising Star
Missing 2023 Showtimes Near Landmark Cinemas Peoria
What Is A Good Estimate For 380 Of 60
Flights To Frankfort Kentucky
Luna Lola: The Moon Wolf book by Park Kara
Scenes from Paradise: Where to Visit Filming Locations Around the World - Paradise
60 X 60 Christmas Tablecloths
CVS Near Me | Columbus, NE
Hobby Stores Near Me Now
Daytonaskipthegames
The BEST Soft and Chewy Sugar Cookie Recipe
Sussyclassroom
Shreveport City Warrants Lookup
Apartments / Housing For Rent near Lake Placid, FL - craigslist
Gs Dental Associates
1145 Barnett Drive
Lovindabooty
Wrights Camper & Auto Sales Llc
The Goonies Showtimes Near Marcus Rosemount Cinema
Viduthalai Movie Download
Craigslist Auburn Al
The Monitor Recent Obituaries: All Of The Monitor's Recent Obituaries
The Posturepedic Difference | Sealy New Zealand
Fedex Walgreens Pickup Times
Envy Nails Snoqualmie
Royals op zondag - "Een advertentie voor Center Parcs" of wat moeten we denken van de laatste video van prinses Kate?
Nacho Libre Baptized Gif
Devotion Showtimes Near Mjr Universal Grand Cinema 16
2008 DODGE RAM diesel for sale - Gladstone, OR - craigslist
Walgreens Agrees to Pay $106.8M to Resolve Allegations It Billed the Government for Prescriptions Never Dispensed
Three V Plymouth
Sdn Fertitta 2024
Unblocked Games Gun Games
Parent Portal Pat Med
My Eschedule Greatpeople Me
15 Best Places to Visit in the Northeast During Summer
Greatpeople.me Login Schedule
Minterns German Shepherds
Walmart Front Door Wreaths
Pulpo Yonke Houston Tx
San Pedro Sula To Miami Google Flights
The Ultimate Guide To 5 Movierulz. Com: Exploring The World Of Online Movies
Latest Posts
Article information

Author: Domingo Moore

Last Updated:

Views: 6151

Rating: 4.2 / 5 (53 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Domingo Moore

Birthday: 1997-05-20

Address: 6485 Kohler Route, Antonioton, VT 77375-0299

Phone: +3213869077934

Job: Sales Analyst

Hobby: Kayaking, Roller skating, Cabaret, Rugby, Homebrewing, Creative writing, amateur radio

Introduction: My name is Domingo Moore, I am a attractive, gorgeous, funny, jolly, spotless, nice, fantastic person who loves writing and wants to share my knowledge and understanding with you.