Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-18384

Опубликовано: 16 окт. 2018
Источник: debian
EPSS Низкий

Описание

Info-ZIP UnZip 6.0 has a buffer overflow in list.c, when a ZIP archive has a crafted relationship between the compressed-size value and the uncompressed-size value, because a buffer size is 10 and is supposed to be 12.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
unzipfixed6.0-11package

Примечания

  • https://bugzilla.suse.com/show_bug.cgi?id=1110194

  • https://sourceforge.net/p/infozip/bugs/53/

  • The cfactorstr buffer was already increased to 12 with the

  • 07-increase-size-of-cfactorstr.patch patch as applied for #741384

  • Upstream confirmed as well this is indeed enough as per

  • https://sourceforge.net/p/infozip/bugs/53/#ba07

EPSS

Процентиль: 85%
0.02754
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 7 лет назад

Info-ZIP UnZip 6.0 has a buffer overflow in list.c, when a ZIP archive has a crafted relationship between the compressed-size value and the uncompressed-size value, because a buffer size is 10 and is supposed to be 12.

CVSS3: 3.3
redhat
почти 7 лет назад

Info-ZIP UnZip 6.0 has a buffer overflow in list.c, when a ZIP archive has a crafted relationship between the compressed-size value and the uncompressed-size value, because a buffer size is 10 and is supposed to be 12.

CVSS3: 5.5
nvd
почти 7 лет назад

Info-ZIP UnZip 6.0 has a buffer overflow in list.c, when a ZIP archive has a crafted relationship between the compressed-size value and the uncompressed-size value, because a buffer size is 10 and is supposed to be 12.

CVSS3: 5.5
msrc
около 5 лет назад

Описание отсутствует

suse-cvrf
больше 6 лет назад

Security update for unzip

EPSS

Процентиль: 85%
0.02754
Низкий