Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-unzip | Mar 26, 2024 | Jan 31, 2020 | |
| Apple Osx Zip | apple-osx-upgrade-latest | Mar 29, 2016 | Mar 29, 2016 | |
| Debian | debian-upgrade-unzip | Jul 30, 2024 | Jan 31, 2020 | |
| Gentoo Linux | gentoo-linux-upgrade-app-arch-unzip | Oct 30, 2017 | Nov 1, 2016 | |
| Oracle Solaris | oracle-solaris-11-2-upgrade-compress-unzip-6-0-0-175-2-7-0-4-0oracle-solaris-11-2-upgrade-library-security-openssl-1-0-1-11-0-175-2-6-0-5-0oracle-solaris-11-2-upgrade-library-security-openssl-openssl-fips-140-2-0-6-0-175-2-6-0-5-0 | May 29, 2017 | May 29, 2017 | |
| Oracle_linux | — | oracle-linux-upgrade-unzip | Oct 16, 2024 | Jan 31, 2020 |
| Ubuntu | ubuntu-upgrade-unzip | Nov 8, 2024 | Jan 31, 2020 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Jan 31, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub