CVE-2022-0529

Related Vulnerabilities: CVE-2022-0529  

A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

Description

A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

Additional Information

  • Bugzilla 2051402: CVE-2022-0529 unzip: Heap out-of-bound writes and reads during conversion of wide string to local string
  • CWE-125: Out-of-bounds Read
  • FAQ: Frequently asked questions about CVE-2022-0529