Out-of-bounds write in UnZip - CVE-2022-0529

 

Out-of-bounds write in UnZip - CVE-2022-0529

Published: August 9, 2022


Vulnerability identifier: #VU66220
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-0529
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing zip archives during the conversion of a UTF-8 string to a local string. A remote attacker can create a specially crafted zip file, trick the victim into opening it using the affected software, trigger out-of-bounds write and execute arbitrary code on the target system.


Affected software

UnZip
Debian Linux
Oracle Solaris
Amazon Linux AMI
Gentoo Linux
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Storage
SUSE Linux Enterprise Server
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
openSUSE Leap
openEuler
Anolis OS
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
cflinuxfs3
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
RecoverPoint for Virtual Machines
IBM Tivoli Application Dependency Discovery Manager
unzip (Ubuntu package)
unzip-doc
unzip
unzip (Debian package)
unzip-debuginfo
unzip-debugsource
unzip-help
RSA Authentication Manager

How to mitigate CVE-2022-0529

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Oracle Solaris - update to 11.4 SRU 71
cflinuxfs3 - update to 0.328.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
IBM Tivoli Application Dependency Discovery Manager - update to 7.3.0.10
unzip (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 6.0-21ubuntu1.2, 6.0-25ubuntu1.1, 6.0-26ubuntu3.1
unzip-doc - update to 6.0-4
unzip - update to 6.0-4
unzip (Debian package) - update to 6.0-26+deb11u1
unzip-debuginfo - addressed in versions 6.00-33.16.1, 6.00-150000.4.11.1
unzip - addressed in versions 6.00-33.16.1, 6.00-150000.4.11.1
unzip-debugsource - addressed in versions 6.00-33.16.1, 6.00-150000.4.11.1
unzip - update to 6.0-46
unzip-debuginfo - update to 6.0-46
unzip-help - update to 6.0-46
unzip-debugsource - update to 6.0-46
unzip - update to 6.0-57
unzip-doc - update to 6.00-150000.4.11.1
RSA Authentication Manager - update to 8.7 Patch 2

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins