Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-15649

Опубликовано: 27 мая 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date. _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die. The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.

A flaw was found in perl-IO-Compress. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by providing a specially crafted zip file. The IO::Uncompress::Unzip module, which is part of perl-IO-Compress, does not properly handle malformed date information within a zip file's header. This can lead to an uncaught error that causes the program to crash, making the affected system unavailable.

Отчет

This Moderate flaw in perl-IO-Compress can lead to a Denial of Service. By processing a specially crafted zip file containing malformed date information in its header, an application utilizing the IO::Uncompress::Unzip module may crash. This vulnerability primarily affects systems where applications handle untrusted compressed archives, potentially leading to service unavailability.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10perl-IO-CompressFix deferred
Red Hat Enterprise Linux 7perl-IO-CompressOut of support scope
Red Hat Enterprise Linux 8perl:5.32/perl-IO-CompressFix deferred
Red Hat Enterprise Linux 8perl-IO-CompressFix deferred
Red Hat Enterprise Linux 9perl-IO-CompressFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1286
https://bugzilla.redhat.com/show_bug.cgi?id=2481766perl-IO-Compress: perl-IO-Compress: Denial of Service via malformed DOS date in zip header

EPSS

Процентиль: 3%
0.00127
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
3 месяца назад

IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date. _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die. The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.

CVSS3: 5.5
nvd
3 месяца назад

IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date. _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die. The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.

CVSS3: 5.5
msrc
3 месяца назад

IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date

CVSS3: 5.5
debian
3 месяца назад

IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaugh ...

CVSS3: 5.5
github
3 месяца назад

IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date. _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die. The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.

EPSS

Процентиль: 3%
0.00127
Низкий

6.5 Medium

CVSS3