unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra field with an uncompressed size smaller than the compressed field size in a zip archive that advertises STORED method compression.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade unzip | Mar 26, 2024 | Feb 6, 2015 |
| Centos_linux | — | Upgrade unzip | Dec 1, 2016 | Feb 6, 2015 |
| Debian | — | Upgrade unzip | Jul 30, 2024 | Feb 6, 2015 |
| Freebsd | — | Upgrade unzip | Dec 10, 2025 | Feb 3, 2015 |
| Gentoo Linux | — | Upgrade app-arch/unzip. | Oct 30, 2017 | Feb 6, 2015 |
| Oracle Solaris | — | Upgrade compress/unzip to version 6.0-0.175.2.10.0.4.0 on Solaris 11.2 | May 29, 2017 | Feb 6, 2015 |
| Oracle_linux | — | Upgrade unzip | Oct 16, 2024 | Feb 6, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 2, 2014 |
| Suse | — | Upgrade unzip-docUpgrade unzip-rccUpgrade unzip | Dec 18, 2015 | Feb 6, 2015 |
| Ubuntu | — | Upgrade unzip | Nov 8, 2024 | Feb 6, 2015 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 6, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub