A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade unzip | Mar 26, 2024 | Feb 9, 2022 |
| Amazon Linux Ami 2 | — | Upgrade unzip-debuginfoUpgrade unzip | Jan 24, 2023 | Feb 9, 2022 |
| Amazon_linux_2023 | — | Upgrade unzip-debuginfoUpgrade unzipUpgrade unzip-debugsource | Feb 17, 2025 | Jan 24, 2022 |
| Debian | — | Upgrade unzip | Sep 26, 2022 | Feb 9, 2022 |
| Gentoo Linux | — | Upgrade app-arch/unzip. | Oct 31, 2023 | Feb 9, 2022 |
| Huawei Euleros 2_0_sp10 | — | Upgrade unzip | May 9, 2022 | Feb 9, 2022 |
| Huawei Euleros 2_0_sp3 | — | Upgrade unzip | May 25, 2022 | Feb 9, 2022 |
| Huawei Euleros 2_0_sp5 | — | Upgrade unzip | Jun 17, 2022 | Feb 9, 2022 |
| Huawei Euleros 2_0_sp9 | — | Upgrade unzip | Jun 16, 2022 | Feb 9, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 9, 2022 |
| Suse | — | Upgrade unzip-docUpgrade unzip | Oct 26, 2022 | Feb 9, 2022 |
| Ubuntu | — | Upgrade unzip (Ubuntu Pro)Upgrade unzip | Oct 13, 2022 | Feb 9, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 9, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub