CVE-2015-7697
published 2015-11-06CVE-2015-7697: Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (infinite loop) via empty bzip2 data in a ZIP archive.
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
6.02%
92.5th percentile
Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (infinite loop) via empty bzip2 data in a ZIP archive.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | unzip | < unzip 6.0-19 (bookworm) | unzip 6.0-19 (bookworm) |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | unzip-6.0-15.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | unzip-6.0-15.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | unzip-6.0-19.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm | — | — |
| msrc | unzip-6.0-19.cm2.x86_64.rpm_on_cbl_mariner_2.0_x64 | — | — |
| msrc | unzip-6.0-20.azl3.aarch64.rpm_on_azure_linux_3.0_arm | — | — |
| msrc | unzip-6.0-20.azl3.x86_64.rpm_on_azure_linux_3.0_x64 | — | — |
| msrc | unzip-debuginfo-6.0-15.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | unzip-debuginfo-6.0-15.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | unzip-debuginfo-6.0-19.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm | — | — |
| msrc | unzip-debuginfo-6.0-19.cm2.x86_64.rpm_on_cbl_mariner_2.0_x64 | — | — |
| unzip_project | unzip | — | — |
| unzip_project | unzip | >= 0 < 6.0-19 | 6.0-19 |
| unzip_project | unzip | >= 0 < 6.0-19 | 6.0-19 |
| unzip_project | unzip | >= 0 < 6.0-19 | 6.0-19 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.8MEDIUM
vendor_ubuntu6.8MEDIUM
vendor_debian4.3MEDIUM
vendor_msrc4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
CVE-2015-7697: Mariner: Mariner
cve@mitre
vendor_msrc·2024-06-11·CVSS 4.3
CVE-2015-7697 [MEDIUM] CVE-2015-7697: Mariner: Mariner
cve@mitre
Mariner: Mariner
[email protected]: [email protected]
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Ubuntu
unzip regression
vendor_ubuntu·2015-11-09·CVSS 6.8
[MEDIUM] unzip regression
Title: unzip regression
Summary: USN-2788-1 introduced a regression in unzip.
USN-2788-1 fixed vulnerabilities in unzip. One of the security patches
caused a regression when extracting 0-byte files. This update fixes the
problem.
We apologize for the inconvenience.
Original advisory details:
Gustavo Grieco discovered that unzip incorrectly handled certain password
protected archives. If a user or automated system were tricked into
processing a specially crafted zip archive, an attacker could possibly
execute arbitrary code. (CVE-2015-7696)
Gustavo Grieco discovered that unzip incorrectly handled certain malformed
archives. If a user or automated system were tricked into processing a
specially crafted zip archive, an attacker could possibly cause unzip to
hang, resulting in a denial o
Ubuntu
unzip vulnerabilities
vendor_ubuntu·2015-10-29·CVSS 6.8
CVE-2015-7696 [MEDIUM] unzip vulnerabilities
Title: unzip vulnerabilities
Summary: unzip could be made to crash or run programs as your login if it opened a
specially crafted file.
Gustavo Grieco discovered that unzip incorrectly handled certain password
protected archives. If a user or automated system were tricked into
processing a specially crafted zip archive, an attacker could possibly
execute arbitrary code. (CVE-2015-7696)
Gustavo Grieco discovered that unzip incorrectly handled certain malformed
archives. If a user or automated system were tricked into processing a
specially crafted zip archive, an attacker could possibly cause unzip to
hang, resulting in a denial of service. (CVE-2015-7697)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
unzip: Heap overflow and DoS in 6.0
vendor_redhat·2015-09-07·CVSS 4.3
CVE-2015-7697 [MEDIUM] unzip: Heap overflow and DoS in 6.0
unzip: Heap overflow and DoS in 6.0
Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (infinite loop) via empty bzip2 data in a ZIP archive.
Package: unzip (Red Hat Enterprise Linux 5) - Will not fix
Package: unzip (Red Hat Enterprise Linux 6) - Will not fix
Package: unzip (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2015-7697: unzip - Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (infinit...
vendor_debian·2015·CVSS 4.3
CVE-2015-7697 [MEDIUM] CVE-2015-7697: unzip - Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (infinit...
Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (infinite loop) via empty bzip2 data in a ZIP archive.
Scope: local
bookworm: resolved (fixed in 6.0-19)
bullseye: resolved (fixed in 6.0-19)
forky: resolved (fixed in 6.0-19)
sid: resolved (fixed in 6.0-19)
trixie: resolved (fixed in 6.0-19)
GHSA
GHSA-8gh7-7428-6468: Info-ZIP UnZip 6
ghsa_unreviewed·2022-05-13
CVE-2015-7697 [MEDIUM] GHSA-8gh7-7428-6468: Info-ZIP UnZip 6
Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (infinite loop) via empty bzip2 data in a ZIP archive.
OSV
unzip regression
osv·2015-11-09·CVSS 6.8
CVE-2015-7696 [MEDIUM] unzip regression
unzip regression
USN-2788-1 fixed vulnerabilities in unzip. One of the security patches
caused a regression when extracting 0-byte files. This update fixes the
problem.
We apologize for the inconvenience.
Original advisory details:
Gustavo Grieco discovered that unzip incorrectly handled certain password
protected archives. If a user or automated system were tricked into
processing a specially crafted zip archive, an attacker could possibly
execute arbitrary code. (CVE-2015-7696)
Gustavo Grieco discovered that unzip incorrectly handled certain malformed
archives. If a user or automated system were tricked into processing a
specially crafted zip archive, an attacker could possibly cause unzip to
hang, resulting in a denial of service. (CVE-2015-7697)
OSV
CVE-2015-7697: Info-ZIP UnZip 6
osv·2015-11-06·CVSS 4.3
CVE-2015-7697 [MEDIUM] CVE-2015-7697: Info-ZIP UnZip 6
Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (infinite loop) via empty bzip2 data in a ZIP archive.
OSV
unzip vulnerabilities
osv·2015-10-29·CVSS 6.8
CVE-2015-7696 [MEDIUM] unzip vulnerabilities
unzip vulnerabilities
Gustavo Grieco discovered that unzip incorrectly handled certain password
protected archives. If a user or automated system were tricked into
processing a specially crafted zip archive, an attacker could possibly
execute arbitrary code. (CVE-2015-7696)
Gustavo Grieco discovered that unzip incorrectly handled certain malformed
archives. If a user or automated system were tricked into processing a
specially crafted zip archive, an attacker could possibly cause unzip to
hang, resulting in a denial of service. (CVE-2015-7697)
No detection rules found.
No public exploits indexed.
http://sourceforge.net/p/infozip/patches/23/http://www.debian.org/security/2015/dsa-3386http://www.openwall.com/lists/oss-security/2015/09/07/4http://www.openwall.com/lists/oss-security/2015/09/15/6http://www.openwall.com/lists/oss-security/2015/10/11/5http://www.securityfocus.com/bid/76863http://www.securitytracker.com/id/1034027http://www.ubuntu.com/usn/USN-2788-1http://www.ubuntu.com/usn/USN-2788-2http://sourceforge.net/p/infozip/patches/23/http://www.debian.org/security/2015/dsa-3386http://www.openwall.com/lists/oss-security/2015/09/07/4http://www.openwall.com/lists/oss-security/2015/09/15/6http://www.openwall.com/lists/oss-security/2015/10/11/5http://www.securityfocus.com/bid/76863http://www.securitytracker.com/id/1034027http://www.ubuntu.com/usn/USN-2788-1http://www.ubuntu.com/usn/USN-2788-2
2015-11-06
Published