CVE-2021-4217
published 2022-08-24CVE-2021-4217: A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows…
PriorityP411low3.3CVSS 3.1
AVLACLPRNUIRSUCNINAL
EPSS
0.57%
43.5th percentile
A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | unzip | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_unzip_6.0-22_on_azure_linux_3.0 | — | — |
| msrc | cbl2_unzip_6.0-22_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_unzip_6.0-19_on_cbl_mariner_1.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| unzip_project | unzip | — | — |
| unzip_project | unzip | — | — |
| unzip_project | unzip | >= 0 < 6.0-21ubuntu1.2 | 6.0-21ubuntu1.2 |
| unzip_project | unzip | >= 0 < 6.0-25ubuntu1.1 | 6.0-25ubuntu1.1 |
| unzip_project | unzip | >= 0 < 6.0-26ubuntu3.1 | 6.0-26ubuntu3.1 |
| unzip_project | unzip | >= 0 < 6.0-9ubuntu1.6+esm1 | 6.0-9ubuntu1.6+esm1 |
| unzip_project | unzip | >= 0 < 6.0-20ubuntu1.1+esm1 | 6.0-20ubuntu1.1+esm1 |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
osv3.3LOW
vendor_debian3.3LOW
vendor_msrc3.3LOW
vendor_redhat3.3LOW
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
unzip vulnerability
vendor_ubuntu·2024-10-03
CVE-2021-4217 unzip vulnerability
Title: unzip vulnerability
Summary: unzip could be made to crash or run programs as your login if it opened a
specially crafted file.
It was discovered that unzip did not properly handle unicode strings under
certain circumstances. If a user were tricked into opening a specially
crafted zip file, an attacker could possibly use this issue to cause unzip
to crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
unzip vulnerabilities
vendor_ubuntu·2022-10-13·CVSS 3.3
CVE-2022-0529 [LOW] unzip vulnerabilities
Title: unzip vulnerabilities
Summary: Several security issues were fixed in unzip.
It was discovered that unzip did not properly handle unicode strings under
certain circumstances. If a user were tricked into opening a specially crafted
zip file, an attacker could possibly use this issue to cause unzip to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2021-4217)
It was discovered that unzip did not properly perform bounds checking while
converting wide strings to local strings. If a user were tricked into opening a
specially crafted zip file, an attacker could possibly use this issue to cause
unzip to crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2022-0529, CVE-2022-0530)
Instructions: In general, a standard system
Microsoft
The vulnerability in unzip occurs due to improper handling of Unicode strings
vendor_msrc·2022-08-09·CVSS 3.3
CVE-2021-4217 [LOW] CWE-476 The vulnerability in unzip occurs due to improper handling of Unicode strings
The vulnerability in unzip occurs due to improper handling of Unicode strings
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Red Hat
unzip: Null pointer dereference in Unicode strings code
vendor_redhat·2022-01-14·CVSS 3.3
CVE-2021-4217 [LOW] CWE-476 unzip: Null pointer dereference in Unicode strings code
unzip: Null pointer dereference in Unicode strings code
A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.
A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.
Package: unzip (Red Hat Enterprise Linux 6) - Out of support scope
Package: unzip (Red Hat Enterprise Linux 7) - Out of support scope
Package: unzip (Red Hat Enterprise Linux 8) - Fix deferred
Package: unzip (Red Hat Enterprise Linux 9) - F
Debian
CVE-2021-4217: unzip - A flaw was found in unzip. The vulnerability occurs due to improper handling of ...
vendor_debian·2021·CVSS 3.3
CVE-2021-4217 [LOW] CVE-2021-4217: unzip - A flaw was found in unzip. The vulnerability occurs due to improper handling of ...
A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
OSV
unzip vulnerabilities
osv·2022-10-13·CVSS 3.3
CVE-2021-4217 [LOW] unzip vulnerabilities
unzip vulnerabilities
It was discovered that unzip did not properly handle unicode strings under
certain circumstances. If a user were tricked into opening a specially crafted
zip file, an attacker could possibly use this issue to cause unzip to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2021-4217)
It was discovered that unzip did not properly perform bounds checking while
converting wide strings to local strings. If a user were tricked into opening a
specially crafted zip file, an attacker could possibly use this issue to cause
unzip to crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2022-0529, CVE-2022-0530)
GHSA
GHSA-9xxw-h585-3vfj: A flaw was found in unzip
ghsa_unreviewed·2022-08-25
CVE-2021-4217 [HIGH] CWE-476 GHSA-9xxw-h585-3vfj: A flaw was found in unzip
A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.
OSV
CVE-2021-4217: A flaw was found in unzip
osv·2022-08-24·CVSS 3.3
CVE-2021-4217 [LOW] CVE-2021-4217: A flaw was found in unzip
A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2021-4217https://bugs.launchpad.net/ubuntu/+source/unzip/+bug/1957077https://bugzilla.redhat.com/show_bug.cgi?id=2044583https://access.redhat.com/security/cve/CVE-2021-4217https://bugs.launchpad.net/ubuntu/+source/unzip/+bug/1957077https://bugzilla.redhat.com/show_bug.cgi?id=2044583
2022-08-24
Published