cbcvebase.
CVE-2022-0529
published 2022-02-09

CVE-2022-0529: A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This…

medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

Affected

23 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianunzip< unzip 6.0-27 (bookworm)unzip 6.0-27 (bookworm)
fedoraprojectfedora
msrcazl3_unzip_6.0-21_on_azure_linux_3.0
msrcazl3_unzip_6.0-22_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_unzip_6.0-21_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_unzip_6.0-19_on_cbl_mariner_1.0
redhatenterprise_linux
unzip_projectunzip
unzip_projectunzip>= 0 < 6.0-26+deb11u16.0-26+deb11u1
unzip_projectunzip>= 0 < 6.0-276.0-27
unzip_projectunzip>= 0 < 6.0-276.0-27
unzip_projectunzip>= 0 < 6.0-276.0-27
unzip_projectunzip>= 0 < 6.0-21ubuntu1.26.0-21ubuntu1.2
unzip_projectunzip>= 0 < 6.0-25ubuntu1.16.0-25ubuntu1.1
unzip_projectunzip>= 0 < 6.0-26ubuntu3.16.0-26ubuntu3.1
unzip_projectunzip>= 0 < 6.0-9ubuntu1.6+esm16.0-9ubuntu1.6+esm1
unzip_projectunzip>= 0 < 6.0-20ubuntu1.1+esm16.0-20ubuntu1.1+esm1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM