CVE-2015-1315Improper Restriction of Operations within the Bounds of a Memory Buffer in Unzip

Severity
7.5HIGHNVD
EPSS
12.1%
top 6.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 23
Latest updateMay 17

Description

Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote attackers to execute arbitrary code via a crafted string, as demonstrated by converting a string from CP866 to UTF-8.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

NVDinfo-zip/unzip6.10b
Ubuntuunzip_project/unzip< 6.0-9ubuntu1.3

Also affects: Ubuntu Linux 12.04, 14.04, 14.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-2xg4-jx3q-qjrp: Buffer overflow in the charset_to_intern function in unix/unix2022-05-17
CVEList
CVE-2015-1315: Buffer overflow in the charset_to_intern function in unix/unix2015-02-23
OSV
CVE-2015-1315: Buffer overflow in the charset_to_intern function in unix/unix2015-02-17

📋Vendor Advisories

3
Red Hat
unzip: charset_to_intern() buffer overflow2015-02-17
Ubuntu
unzip vulnerabilities2015-02-17
Debian
CVE-2015-1315: unzip - Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZ...2015

💬Community

1
Bugzilla
CVE-2015-1315 unzip: charset_to_intern() buffer overflow2015-02-13
CVE-2015-1315 — Info-zip Unzip vulnerability | cvebase