Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-1000035

Опубликовано: 09 фев. 2018
Источник: debian

Описание

A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a denial of service or to possibly achieve code execution.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
unzipfixed6.0-22package
unzipfixed6.0-21+deb9u1stretchpackage
unzipno-dsawheezypackage

Примечания

  • https://www.sec-consult.com/en/blog/advisories/multiple-vulnerabilities-in-infozip-unzip/index.html

  • Patch used in openSUSE:Factory/unzip: https://bugzilla.suse.com/attachment.cgi?id=759406

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 7 лет назад

A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a denial of service or to possibly achieve code execution.

CVSS3: 7
redhat
больше 7 лет назад

A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a denial of service or to possibly achieve code execution.

CVSS3: 7.8
nvd
больше 7 лет назад

A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a denial of service or to possibly achieve code execution.

CVSS3: 7.8
msrc
почти 5 лет назад

Описание отсутствует

suse-cvrf
больше 7 лет назад

Security update for unzip