6.8
CVSSv2

CVE-2015-7696

Published: 06/11/2015 Updated: 16/12/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 606
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Info-ZIP UnZip 6.0 allows remote malicious users to cause a denial of service (heap-based buffer over-read and application crash) or possibly execute arbitrary code via a crafted password-protected ZIP archive, possibly related to an Extra-Field size value.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 14.04

canonical ubuntu linux 12.04

canonical ubuntu linux 15.10

canonical ubuntu linux 15.04

debian debian linux 7.0

debian debian linux 8.0

unzip project unzip 6.0

Vendor Advisories

Debian Bug report logs - #802162 CVE-2015-7696: unzip: Heap buffer overflow when extracting password-protected archive Package: unzip; Maintainer for unzip is Santiago Vila <sanvila@debianorg>; Source for unzip is src:unzip (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Date: Sat, 17 Oct 2015 20:54:06 ...
Debian Bug report logs - #802160 CVE-2015-7697: unzip: Infinite loop when extracting password-protected archive Package: unzip; Maintainer for unzip is Santiago Vila <sanvila@debianorg>; Source for unzip is src:unzip (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Date: Sat, 17 Oct 2015 20:42:01 UTC S ...
Two vulnerabilities have been found in unzip, a de-archiver for zip files The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-7696 Gustavo Grieco discovered that unzip incorrectly handled certain password protected archives If a user or automated system were tricked into processing a speciall ...
USN-2788-1 introduced a regression in unzip ...
unzip could be made to crash or run programs as your login if it opened a specially crafted file ...