4.3
CVSSv2

CVE-2014-9485

Published: 16/01/2018 Updated: 24/01/2024
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in the do_extract_currentfile function in miniunz.c in miniunzip in minizip prior to 1.1-5 might allow remote malicious users to write to arbitrary files via a crafted entry in a ZIP archive.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

minizip project minizip

Vendor Advisories

Debian Bug report logs - #774321 minizip: CVE-2014-9485: directory traversal Package: minizip; Maintainer for minizip is Michael Gilbert <mgilbert@debianorg>; Source for minizip is src:minizip (PTS, buildd, popcon) Reported by: Jakub Wilk <jwilk@debianorg> Date: Wed, 31 Dec 2014 18:03:02 UTC Severity: important Ta ...

Mailing Lists

On 10/20/23 11:42, Alan Coopersmith wrote: The fix was included in this week's zlib 131 release: githubcom/madler/zlib/releases/tag/v131 That release also contains a fix for CVE-2014-9485, a path traversal vulnerability, in the miniunz program from the minizip contrib directory: githubcom/madler/zlib/commit/14a5f8f266c16c87 ...

Github Repositories

C++ wrapper around minizip compression library

⚠️ This project and particularly this master branch is no longer maintained The new repo is: githubcom/Lecrapouille/zipper based on githubcom/sebastiandev/zipper/tree/v2xy C++ wrapper around minizip compression library Zipper's goal is to bring the power and simplicity of minizip to a more object oriented/c++ user friendly library It was born out