#VU33148 Out-of-bounds read in UnZip - CVE-2015-7696
Published: November 6, 2015 / Updated: August 3, 2020
UnZip
Info-ZIP
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in Info-ZIP UnZip 6.0. A remote attacker can perform a denial of service (heap-based buffer over-read and application crash) or possibly execute arbitrary code via a crafted password-protected ZIP archive, possibly related to an Extra-Field size value.
Remediation
External links
- http://www.debian.org/security/2015/dsa-3386
- http://www.openwall.com/lists/oss-security/2015/09/07/4
- http://www.openwall.com/lists/oss-security/2015/09/15/6
- http://www.openwall.com/lists/oss-security/2015/09/21/6
- http://www.openwall.com/lists/oss-security/2015/10/11/5
- http://www.securityfocus.com/bid/76863
- http://www.securitytracker.com/id/1034027
- http://www.ubuntu.com/usn/USN-2788-1
- http://www.ubuntu.com/usn/USN-2788-2