5.5
CVSSv3

CVE-2022-0529

Published: 09/02/2022 Updated: 09/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an malicious user to input a specially crafted zip file, leading to a crash or code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

unzip project unzip 6.0

redhat enterprise linux 8.0

fedoraproject fedora 35

debian debian linux 10.0

debian debian linux 11.0

Vendor Advisories

Several security issues were fixed in unzip ...
Sandipan Roy discovered two vulnerabilities in InfoZIP's unzip program, a de-archiver for zip files, which could result in denial of service or potentially the execution of arbitrary code For the stable distribution (bullseye), these problems have been fixed in version 60-26+deb11u1 We recommend that you upgrade your unzip packages For the det ...
A flaw was found in unzip The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution (CVE-2021-4217) A flaw was found in Unzip The vulnerability occurs during the conversion of a wide ...
A flaw was found in Unzip The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution ...
ALAS-2022-221 Amazon Linux 2022 Security Advisory: ALAS-2022-221 Advisory Release Date: 2022-12-06 16:42 Pacific ...

Github Repositories

CVE-2022-0529 & CVE-2022-0530

POC for unzip 60 CVE-2022-0529 & CVE-2022-0530 bugzillaredhatcom/show_bugcgi?id=2051402 bugzillaredhatcom/show_bugcgi?id=2051395

CVE-2022-0529 & CVE-2022-0530

CVE-2022-0529 and CVE-2022-0530 POC for unzip 60 CVE-2022-0529 & CVE-2022-0530 bugzillaredhatcom/show_bugcgi?id=2051402 bugzillaredhatcom/show_bugcgi?id=2051395