Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8141

Опубликовано: 22 дек. 2014
Источник: redhat
CVSS2: 2.6
EPSS Низкий

Описание

Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

A buffer overflow flaw was found in the way unzip handled Zip64 files. A specially crafted Zip archive could possibly cause unzip to crash when the archive was uncompressed.

Отчет

This issue did not affect the versions of unzip as shipped with Red Hat Enterprise Linux 5 as they did not include support for Zip64.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5unzipNot affected
Red Hat Enterprise Linux 6unzipFixedRHSA-2015:070018.03.2015
Red Hat Enterprise Linux 7unzipFixedRHSA-2015:070018.03.2015

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1174856unzip: getZip64Data() out-of-bounds read issues (oCERT-2014-011)

EPSS

Процентиль: 93%
0.09912
Низкий

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 5 лет назад

Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

CVSS3: 7.8
nvd
больше 5 лет назад

Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

CVSS3: 7.8
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 7.8
debian
больше 5 лет назад

Heap-based buffer overflow in the getZip64Data function in Info-ZIP Un ...

CVSS3: 7.8
github
около 3 лет назад

Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

EPSS

Процентиль: 93%
0.09912
Низкий

2.6 Low

CVSS2