Lucene search

K
archlinuxArch LinuxASA-201501-3
HistoryJan 10, 2015 - 12:00 a.m.

unzip: arbitrary code execution

2015-01-1000:00:00
Arch Linux
lists.archlinux.org
20

0.007 Low

EPSS

Percentile

79.6%

  • CVE-2014-8139 (heap buffer overflow)
    A heap-based buffer overflow exists in the CRC32 verification that
    allows attackers to potentially execute arbitrary code or cause a denial
    of service (memory corruption).

  • CVE-2014-8140 (out-of-bounds read/write)
    Out-of-bounds access (both read and write) issues exist in
    test_compr_eb() that can result in application crash or arbitrary code
    execution.

  • CVE-2014-8141 (out-of-bounds read)
    Two out-of-bounds read issues exist in getZip64Data() that allows
    attackers to cause a denial of service.

OSVersionArchitecturePackageVersionFilename
anyanyanyunzip< 6.0-9UNKNOWN