[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2015-504 --- unzip

ID: oval:org.secpod.oval:def:1200014Date: (C)2015-12-29   (M)2024-02-19
Class: PATCHFamily: unix




A buffer overflow was found in the way unzip uncompressed certain extra fields of a file. A specially crafted Zip archive could cause unzip to crash or, possibly, execute arbitrary code when the archive was tested with unzip"s "-t" option. A buffer overflow flaw was found in the way unzip computed the CRC32 checksum of certain extra fields of a file. A specially crafted Zip archive could cause unzip to crash when the archive was tested with unzip"s "-t" option. An integer underflow flaw, leading to a buffer overflow, was found in the way unzip uncompressed certain extra fields of a file. A specially crafted Zip archive could cause unzip to crash when the archive was tested with unzip"s "-t" option. A buffer overflow flaw was found in the way unzip handled Zip64 files. A specially crafted Zip archive could possibly cause unzip to crash when the archive was uncompressed

Platform:
Amazon Linux AMI
Product:
unzip
Reference:
ALAS-2015-504
CVE-2014-8139
CVE-2014-8141
CVE-2014-8140
CVE-2014-9636
CVE    4
CVE-2014-9636
CVE-2014-8141
CVE-2014-8140
CVE-2014-8139
...
CPE    3
cpe:/o:amazon:linux
cpe:/a:info-zip:unzip
cpe:/a:info-zip:unzip:6.0

© SecPod Technologies