cbcvebase.
CVE-2018-1000035
published 2018-02-09

CVE-2018-1000035: A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a…

PriorityP349high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
30.47%
98.0th percentile
A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a denial of service or to possibly achieve code execution.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianunzip< unzip 6.0-22 (bookworm)unzip 6.0-22 (bookworm)
msrcazl3_unzip_6.0-20_on_azure_linux_3.0
msrcazl3_unzip_6.0-22_on_azure_linux_3.0
msrccbl2_unzip_6.0-19_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_unzip_6.0-16_on_cbl_mariner_1.0
msrcunzip-6.0-16.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcunzip-6.0-16.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
msrcunzip-6.0-19.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm
msrcunzip-6.0-19.cm2.x86_64.rpm_on_cbl_mariner_2.0_x64
msrcunzip-6.0-20.azl3.aarch64.rpm_on_azure_linux_3.0_arm
msrcunzip-6.0-20.azl3.x86_64.rpm_on_azure_linux_3.0_x64
msrcunzip-debuginfo-6.0-16.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcunzip-debuginfo-6.0-16.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
msrcunzip-debuginfo-6.0-19.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm
msrcunzip-debuginfo-6.0-19.cm2.x86_64.rpm_on_cbl_mariner_2.0_x64
unzip_projectunzip<= 6.00
unzip_projectunzip>= 0 < 6.0-226.0-22
unzip_projectunzip>= 0 < 6.0-226.0-22
unzip_projectunzip>= 0 < 6.0-226.0-22
unzip_projectunzip>= 0 < 6.0-226.0-22
unzip_projectunzip>= 0 < 6.0-20ubuntu1.16.0-20ubuntu1.1

Detection & IOCsextracted from sources · hover to see the quote

pathfileio.c:UzpPassword
  • The vulnerable code path is in the UzpPassword function in fileio.c. The heap overflow is triggered via a sprintf call building a password prompt using attacker-controlled filenames from inside the ZIP archive. Monitor for unzip processing password-protected ZIP files with unusually long filenames (exceeding FILNAMSIZ bounds).
  • The overflow is triggered specifically when processing password-protected ZIP archives containing files with attacker-controlled, excessively long names. Detection should focus on unzip invocations against password-protected archives (-P flag or interactive password prompt) with embedded long filenames.
  • Affected versions are Info-Zip UnZip <= 6.00. Audit installed unzip versions across systems; any deployment at or below 6.00 processing untrusted ZIP files is at risk. Debian fixed in 6.0-22; Fedora fixed in unzip-6.0-37.
  • ·Red Hat Enterprise Linux 5, 6, and 7 ship affected versions of unzip and are marked 'Will not fix'. RHEL 8 is not affected. Deployments on these RHEL versions should treat any unzip processing of untrusted password-protected ZIPs as a persistent risk.
  • ·The vulnerability is scoped as local exploitation (per Debian security tracker), meaning the attacker must be able to supply a crafted ZIP file to a user or automated system that invokes unzip with password processing.

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.