Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade unzip | Mar 26, 2024 | Jan 31, 2020 |
| Apple Osx Adminframework | — | Upgrade macOS to the latest versionApply OS X security update 2015-005 | Aug 28, 2015 | Aug 28, 2015 |
| Apple Osx Zip | — | Upgrade macOS to the latest version | Mar 29, 2016 | Mar 29, 2016 |
| Centos_linux | — | Upgrade unzip | Aug 17, 2018 | Jan 14, 2015 |
| Debian | — | Upgrade unzip | Jul 30, 2024 | Jan 31, 2020 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Sep 16, 2015 |
| Freebsd | — | Upgrade unzip | Dec 10, 2025 | Jan 16, 2015 |
| Gentoo Linux | — | Upgrade app-arch/unzip. | Oct 30, 2017 | Nov 1, 2016 |
| Oracle Solaris | — | Upgrade library/security/openssl/openssl-fips-140 to version 2.0.6-0.175.2.6.0.5.0 on Solaris 11.2Upgrade library/security/openssl to version 1.0.1.11-0.175.2.6.0.5.0 on Solaris 11.2Upgrade compress/unzip to version 6.0-0.175.2.7.0.4.0 on Solaris 11.2 | May 29, 2017 | May 29, 2017 |
| Oracle_linux | — | Upgrade unzip | Oct 16, 2024 | Jan 31, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 31, 2020 |
| Suse | — | Upgrade unzip-docUpgrade unzip | Dec 18, 2015 | Jan 12, 2015 |
| Ubuntu | — | Upgrade unzip | Nov 8, 2024 | Jan 31, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 31, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub