Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8139

Опубликовано: 22 дек. 2014
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

A buffer overflow flaw was found in the way unzip computed the CRC32 checksum of certain extra fields of a file. A specially crafted Zip archive could cause unzip to crash when the archive was tested with unzip's '-t' option.

Отчет

Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Low security impact and is not currently planned to be addressed in future updates in Red Hat Enterprise Linux 5. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5unzipWill not fix
Red Hat Enterprise Linux 6unzipFixedRHSA-2015:070018.03.2015
Red Hat Enterprise Linux 7unzipFixedRHSA-2015:070018.03.2015

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-190->CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1174844unzip: CRC32 verification heap-based buffer overread (oCERT-2014-011)

EPSS

Процентиль: 93%
0.09912
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 5 лет назад

Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

CVSS3: 7.8
nvd
больше 5 лет назад

Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

CVSS3: 7.8
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 7.8
debian
больше 5 лет назад

Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip ...

CVSS3: 7.8
github
около 3 лет назад

Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

EPSS

Процентиль: 93%
0.09912
Низкий

4.3 Medium

CVSS2