CVE-2015-7696

CWE-119Buffer Overflow11 documents9 sources
Severity
6.8MEDIUM
EPSS
31.3%
top 3.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 6
Latest updateJun 11

Description

Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly execute arbitrary code via a crafted password-protected ZIP archive, possibly related to an Extra-Field size value.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages3 packages

Debianunzip< 6.0-19+3
Ubuntuunzip< 6.0-9ubuntu1.5+1

Also affects: Debian Linux 7.0, 8.0, Ubuntu Linux 12.04, 14.04, 15.04, 15.10

🔴Vulnerability Details

5
GHSA
GHSA-5v9p-v8p9-4mjc: Info-ZIP UnZip 62022-05-13
OSV
unzip regression2015-11-09
CVEList
CVE-2015-7696: Info-ZIP UnZip 62015-11-06
OSV
CVE-2015-7696: Info-ZIP UnZip 62015-11-06
OSV
unzip vulnerabilities2015-10-29

📋Vendor Advisories

4
Microsoft
CVE-2015-7696: Mariner: Mariner cve@mitre2024-06-11
Ubuntu
unzip vulnerabilities2015-10-29
Red Hat
unzip: Heap overflow and DoS in 6.02015-09-07
Debian
CVE-2015-7696: unzip - Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-ba...2015

💬Community

1
Bugzilla
CVE-2015-7696 CVE-2015-7697 unzip: Heap overflow and DoS in 6.02015-09-08