vendor:
unzip
by:
DVDMAN (DVDMAN@L33TSECURITY.COM)
7.5
CVSS
HIGH
Filename buffer-overflow
Not mentioned
CWE
Product Name: unzip
Affected Version From: lame unzip <= 5.50
Affected Version To: Not mentioned
Patch Exists: No
Related CWE: Not mentioned
CPE: Not mentioned
Platforms Tested: Redhat 7.2
Not mentioned
Info-ZIP ‘unzip’ Filename Buffer Overflow Vulnerability
This vulnerability in Info-ZIP 'unzip' allows attackers to execute arbitrary machine code in the context of users running the affected application. The issue arises due to the application's failure to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
Mitigation:
It is recommended to update Info-ZIP 'unzip' to a version that has addressed this vulnerability. No specific mitigation steps mentioned.