CVE-2015-7697

CWE-39911 documents9 sources
Severity
4.3MEDIUM
EPSS
27.6%
top 3.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 6
Latest updateJun 11

Description

Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (infinite loop) via empty bzip2 data in a ZIP archive.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

Debianunzip< 6.0-19+3

Also affects: Debian Linux 7.0, 8.0, Ubuntu Linux 12.04, 14.04, 15.04, 15.10

🔴Vulnerability Details

5
GHSA
GHSA-8gh7-7428-6468: Info-ZIP UnZip 62022-05-13
OSV
unzip regression2015-11-09
CVEList
CVE-2015-7697: Info-ZIP UnZip 62015-11-06
OSV
CVE-2015-7697: Info-ZIP UnZip 62015-11-06
OSV
unzip vulnerabilities2015-10-29

📋Vendor Advisories

4
Microsoft
CVE-2015-7697: Mariner: Mariner cve@mitre2024-06-11
Ubuntu
unzip vulnerabilities2015-10-29
Red Hat
unzip: Heap overflow and DoS in 6.02015-09-07
Debian
CVE-2015-7697: unzip - Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (infinit...2015

💬Community

1
Bugzilla
CVE-2015-7696 CVE-2015-7697 unzip: Heap overflow and DoS in 6.02015-09-08