CVE-2015-1315
published 2015-02-23CVE-2015-1315: Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote attackers to execute arbitrary code via a crafted…
PriorityP341high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.90%
91.1th percentile
Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote attackers to execute arbitrary code via a crafted string, as demonstrated by converting a string from CP866 to UTF-8.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | unzip | — | — |
| info-zip | unzip | — | — |
| unzip_project | unzip | >= 0 < 6.0-9ubuntu1.3 | 6.0-9ubuntu1.3 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
unzip: charset_to_intern() buffer overflow
vendor_redhat·2015-02-17·CVSS 7.5
CVE-2015-1315 [HIGH] CWE-120 unzip: charset_to_intern() buffer overflow
unzip: charset_to_intern() buffer overflow
Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote attackers to execute arbitrary code via a crafted string, as demonstrated by converting a string from CP866 to UTF-8.
Statement: Not vulnerable. This issue did not affect the version of unzip as shipped in Red Hat Enterprise Linux 5, 6, and 7.
Package: unzip (Red Hat Enterprise Linux 5) - Not affected
Package: unzip (Red Hat Enterprise Linux 6) - Not affected
Package: unzip (Red Hat Enterprise Linux 7) - Not affected
Ubuntu
unzip vulnerabilities
vendor_ubuntu·2015-02-17
CVE-2015-1315 unzip vulnerabilities
Title: unzip vulnerabilities
Summary: unzip could be made to run programs if it opened a specially crafted file.
William Robinet discovered that unzip incorrectly handled certain
malformed zip archives. If a user or automated system were tricked into
processing a specially crafted zip archive, an attacker could possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2015-1315: unzip - Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZ...
vendor_debian·2015·CVSS 7.5
CVE-2015-1315 [HIGH] CVE-2015-1315: unzip - Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZ...
Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote attackers to execute arbitrary code via a crafted string, as demonstrated by converting a string from CP866 to UTF-8.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-2xg4-jx3q-qjrp: Buffer overflow in the charset_to_intern function in unix/unix
ghsa_unreviewed·2022-05-17
CVE-2015-1315 [HIGH] CWE-119 GHSA-2xg4-jx3q-qjrp: Buffer overflow in the charset_to_intern function in unix/unix
Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote attackers to execute arbitrary code via a crafted string, as demonstrated by converting a string from CP866 to UTF-8.
OSV
CVE-2015-1315: Buffer overflow in the charset_to_intern function in unix/unix
osv·2015-02-17·CVSS 7.5
CVE-2015-1315 [HIGH] CVE-2015-1315: Buffer overflow in the charset_to_intern function in unix/unix
Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote attackers to execute arbitrary code via a crafted string, as demonstrated by converting a string from CP866 to UTF-8.
Suricata
ET WEB_SPECIFIC_APPS WEB-PHP RCE PHPBB 2004-1315
suricata·2015-07-07
CVE-2004-1315 ET WEB_SPECIFIC_APPS WEB-PHP RCE PHPBB 2004-1315
ET WEB_SPECIFIC_APPS WEB-PHP RCE PHPBB 2004-1315
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS WEB-PHP RCE PHPBB 2004-1315"; flow:established,to_server; http.uri; content:"viewtopic.php"; nocase; content:"highlight="; nocase; http.uri.raw; pcre:"/[&?]highlight=[^&]*?\x2525[a-f0-9]{2}/i"; reference:cve,2004-1315; classtype:web-application-attack; sid:2021390; rev:3; metadata:created_at 2015_07_07, cve CVE_2004_1315, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_05_28;)
No public exploits indexed.
http://www.conostix.com/pub/adv/CVE-2015-1315-Info-ZIP-unzip-Out-of-bounds_Write.txthttp://www.openwall.com/lists/oss-security/2015/02/17/4http://www.ubuntu.com/usn/USN-2502-1https://bugs.launchpad.net/ubuntu/+source/unzip/+bug/580961/comments/120http://www.conostix.com/pub/adv/CVE-2015-1315-Info-ZIP-unzip-Out-of-bounds_Write.txthttp://www.openwall.com/lists/oss-security/2015/02/17/4http://www.ubuntu.com/usn/USN-2502-1https://bugs.launchpad.net/ubuntu/+source/unzip/+bug/580961/comments/120
2015-02-23
Published