Heap Overflow Vulnerability in Info-ZIP UnZip 6.0
CVE-2015-7696

Currently unrated

Key Information:

Vendor
Canonical
Vendor
CVE Published:
6 November 2015

Summary

The vulnerability in Info-ZIP UnZip 6.0 allows remote attackers to exploit a heap-based buffer over-read that can lead to an application crash or potentially allow the execution of arbitrary code. This can occur when a crafted password-protected ZIP archive is processed, with the exploit possibly linked to an inappropriate Extra-Field size value within the archive. Users and administrators are advised to take precautionary measures against this susceptibility to ensure their systems remain secure.

References

EPSS Score

34% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.