Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Unzip
(Unzip_project)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 16 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2008-03-17 | CVE-2008-0888 | The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data. | Mac_os_x, Ubuntu_linux, Debian_linux, Unzip | N/A | ||
2022-02-09 | CVE-2022-0530 | A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution. | Mac_os_x, Macos, Debian_linux, Fedora, Enterprise_linux, Unzip | 5.5 | ||
2022-02-09 | CVE-2022-0529 | A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution. | Debian_linux, Fedora, Enterprise_linux, Unzip | 5.5 | ||
2022-08-24 | CVE-2021-4217 | A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution. | Fedora, Enterprise_linux, Unzip | 3.3 | ||
2022-12-27 | CVE-2020-36561 | Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. | Unzip | 9.1 | ||
2019-07-04 | CVE-2019-13232 | Info-ZIP UnZip 6.0 mishandles the overlapping of files inside a ZIP container, leading to denial of service (resource consumption), aka a "better zip bomb" issue. | Debian_linux, Unzip | 3.3 |