CVE-2014-8140
Severity
7.8HIGH
EPSS
8.1%
top 7.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 31
Latest updateMay 17
Description
Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages6 packages
Also affects: Enterprise Linux 6.6, 7.3, 7.4, 7.6, 7.7, 7.1, 7.2, 7.5
🔴Vulnerability Details
3GHSA▶
GHSA-fhf3-rjhh-4c23: Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6↗2022-05-17
CVEList▶
CVE-2014-8140: Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6↗2020-01-31
OSV▶
CVE-2014-8140: Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6↗2020-01-31
📋Vendor Advisories
5Microsoft▶
Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the un↗2020-01-14
Debian▶
CVE-2014-8140: unzip - Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 a...↗2014