7.5
CVSSv2

CVE-2015-1315

Published: 23/02/2015 Updated: 24/02/2015
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote malicious users to execute arbitrary code via a crafted string, as demonstrated by converting a string from CP866 to UTF-8.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 14.10

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

info-zip unzip 6.10b

Vendor Advisories

unzip could be made to run programs if it opened a specially crafted file ...

Exploits

InfoZip UnZip versions 600 and below and 61c22 and below suffer from multiple buffer overflow vulnerabilities ...