CVE-2015-7696
EPSS 34.9%unzip - security update
發布日:2015/11/6修改日:2026/4/28
描述
Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly execute arbitrary code via a crafted password-protected ZIP archive, possibly related to an Extra-Field size value.
受影響套件(4)
- Alpine/unzipfrom 0, < 6.0-r1
- Debian/unzipfrom 0, < 6.0-19
- Debian/unzipfrom 0, < 6.0-4+deb6u3
- Debian/unzipfrom 0, < 6.0-8+deb7u4