unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra field with an uncompressed size smaller than the compressed field size in a zip archive that advertises STORED method compression.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
21 Nov 2024, 02:21
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.fedoraproject.org/pipermail/package-announce/2015-January/148792.html - | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2015-January/148849.html - | |
References | () http://seclists.org/oss-sec/2014/q4/1131 - | |
References | () http://seclists.org/oss-sec/2014/q4/489 - | |
References | () http://seclists.org/oss-sec/2014/q4/496 - | |
References | () http://seclists.org/oss-sec/2015/q1/216 - | |
References | () http://secunia.com/advisories/62738 - | |
References | () http://secunia.com/advisories/62751 - | |
References | () http://www.debian.org/security/2015/dsa-3152 - | |
References | () http://www.info-zip.org/phpBB3/viewtopic.php?f=7&t=450 - Patch, Vendor Advisory | |
References | () http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html - | |
References | () http://www.securityfocus.com/bid/71825 - | |
References | () http://www.ubuntu.com/usn/USN-2489-1 - | |
References | () https://security.gentoo.org/glsa/201611-01 - |
Information
Published : 2015-02-06 15:59
Updated : 2024-11-21 02:21
NVD link : CVE-2014-9636
Mitre link : CVE-2014-9636
CVE.ORG link : CVE-2014-9636
JSON object : View
Products Affected
debian
- debian_linux
unzip_project
- unzip
fedoraproject
- fedora
canonical
- ubuntu_linux
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer