Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8140

Опубликовано: 22 дек. 2014
Источник: redhat
CVSS2: 4.3

Описание

Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

An integer underflow flaw, leading to a buffer overflow, was found in the way unzip uncompressed certain extra fields of a file. A specially crafted Zip archive could cause unzip to crash when the archive was tested with unzip's '-t' option.

Отчет

Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Low security impact and is not currently planned to be addressed in future updates in Red Hat Enterprise Linux 5. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5unzipWill not fix
Red Hat Enterprise Linux 6unzipFixedRHSA-2015:070018.03.2015
Red Hat Enterprise Linux 7unzipFixedRHSA-2015:070018.03.2015

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20->CWE-190->CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=1174851unzip: out-of-bounds write issue in test_compr_eb() (oCERT-2014-011)

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 5 лет назад

Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

CVSS3: 7.8
nvd
больше 5 лет назад

Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

CVSS3: 7.8
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 7.8
debian
больше 5 лет назад

Heap-based buffer overflow in the test_compr_eb function in Info-ZIP U ...

CVSS3: 7.8
github
около 3 лет назад

Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

4.3 Medium

CVSS2