Input validation error in UnZip - CVE-2016-9844
Published: March 21, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in the zi_short() function in zipinfo.c when processing a large compression method value in the central directory file header. A remote attacker can pass a specially crafted array to the application and trigger denial of service (DoS) condition.
Affected software
unzip (Alpine package)
unzip (Ubuntu package)
unzip
Ubuntu
Slackware Linux
Fedora
Opensuse
How to mitigate CVE-2016-9844
unzip (Ubuntu package) - addressed in versions 6.0-4ubuntu2.6, 6.0-20ubuntu1.1, 6.0-21ubuntu1.1, 6.0-28ubuntu4.1
unzip - addressed in versions 6.0-31.fc24, 6.0-31.fc25