Note:
This project will be discontinued after December 13, 2021. [more]
2020-01-31
Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.
Products | Enterprise_linux_desktop, Enterprise_linux_server, Enterprise_linux_server_eus, Enterprise_linux_server_tus, Enterprise_linux_workstation, Unzip |
Type | Out-of-bounds Write (CWE-787) |
First patch | - None (likely due to unavailable code) |
Links |
• http://www.securitytracker.com/id/1031433
• http://www.ocert.org/advisories/ocert-2014-011.html • https://bugzilla.redhat.com/show_bug.cgi?id=1174856 • https://access.redhat.com/errata/RHSA-2015:0700 |