[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2023-2023-029 --- unzip

ID: oval:org.secpod.oval:def:19500131Date: (C)2023-06-12   (M)2023-12-07
Class: PATCHFamily: unix




A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution. A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution. A flaw was found in Unzip. The vulnerability occurs during the conversion of a UTF-8 string to a local string that leads to a segmentation fault. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution

Platform:
Amazon Linux 2023
Product:
unzip
Reference:
ALAS2023-2023-029
CVE-2021-4217
CVE-2022-0529
CVE-2022-0530
CVE    3
CVE-2021-4217
CVE-2022-0529
CVE-2022-0530
CPE    1
cpe:/a:info-zip:unzip

© SecPod Technologies