Buffer overflow in UnZip - CVE-2014-9913
Published: January 18, 2017 / Updated: August 3, 2020
Vulnerability identifier: #VU33147
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-9913
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local non-authenticated attacker to perform service disruption.
Buffer overflow in the list_files function in list.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via vectors related to the compression method.
Affected software
UnZip
unzip (Alpine package)
unzip (Ubuntu package)
Ubuntu
Opensuse
unzip (Alpine package)
unzip (Ubuntu package)
Ubuntu
Opensuse
How to mitigate CVE-2014-9913
Install update from vendor's website.
UnZip - update to 6.10 b
unzip (Alpine package) - update to 6.0-r3
unzip (Ubuntu package) - addressed in versions 6.0-4ubuntu2.6, 6.0-20ubuntu1.1, 6.0-21ubuntu1.1, 6.0-28ubuntu4.1
unzip (Alpine package) - update to 6.0-r3
unzip (Ubuntu package) - addressed in versions 6.0-4ubuntu2.6, 6.0-20ubuntu1.1, 6.0-21ubuntu1.1, 6.0-28ubuntu4.1
External References
- http://www.openwall.com/lists/oss-security/2014/11/03/5
- http://www.openwall.com/lists/oss-security/2016/12/05/13
- http://www.openwall.com/lists/oss-security/2016/12/05/19
- http://www.openwall.com/lists/oss-security/2016/12/05/20
- http://www.securityfocus.com/bid/95081
- https://bugs.launchpad.net/ubuntu/+source/unzip/+bug/1643750