Lucene search

K
osvGoogleOSV:DSA-1522-1
HistoryMar 17, 2008 - 12:00 a.m.

unzip - potential code execution

2008-03-1700:00:00
Google
osv.dev
10

0.072 Low

EPSS

Percentile

94.0%

Tavis Ormandy discovered that unzip, when processing specially crafted
ZIP archives, could pass invalid pointers to the C library’s free
routine, potentially leading to arbitrary code execution
(CVE-2008-0888).

For the old stable distribution (sarge), this problem has been fixed
in version 5.52-1sarge5.

For the stable distribution (etch), this problem has been fixed in
version 5.52-9etch1.

The unstable distribution (sid) will be fixed soon.

We recommend that you upgrade your unzip package.

CPENameOperatorVersion
unzipeq5.52-9