A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.
CVSS Details
- CVSS 3.1 Base Score: 3.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade unzip | Mar 26, 2024 | Aug 24, 2022 |
| Amazon Linux Ami 2 | — | Upgrade unzipUpgrade unzip-debuginfo | Jan 24, 2023 | Aug 24, 2022 |
| Amazon_linux_2023 | — | Upgrade unzip-debuginfoUpgrade unzipUpgrade unzip-debugsource | Feb 17, 2025 | Jan 14, 2022 |
| Debian | — | No solution exists | May 15, 2025 | Aug 24, 2022 |
| Huawei Euleros 2_0_sp10 | — | Upgrade unzip | Dec 22, 2022 | Aug 24, 2022 |
| Huawei Euleros 2_0_sp8 | — | Upgrade unzip | Dec 9, 2022 | Aug 24, 2022 |
| Huawei Euleros 2_0_sp9 | — | Upgrade unzip | Nov 15, 2022 | Aug 24, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 24, 2022 |
| Ubuntu | — | Upgrade unzipUpgrade unzip (Ubuntu Pro) | Oct 13, 2022 | Aug 24, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Aug 24, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub