CVE-2015-7696
EPSS 34.9%unzip - security update
Published: 11/6/2015Modified: 4/28/2026
Description
Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly execute arbitrary code via a crafted password-protected ZIP archive, possibly related to an Extra-Field size value.
Affected packages (4)
- Alpine/unzipfrom 0, < 6.0-r1
- Debian/unzipfrom 0, < 6.0-19
- Debian/unzipfrom 0, < 6.0-4+deb6u3
- Debian/unzipfrom 0, < 6.0-8+deb7u4