cbcvebase.
CVE-2022-0530
published 2022-02-09

CVE-2022-0530: A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This…

medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
applemac_os_x
applemac_os_x>= 10.15 < 10.15.710.15.7
applemacos>= 11.0 < 11.6.611.6.6
applemacos>= 12.0.0 < 12.412.4
applemacos_big_sur
applemacos_monterey
applesecurity_update_2022-004_catalina
debiandebian_linux
debiandebian_linux
debianunzip< unzip 6.0-27 (bookworm)unzip 6.0-27 (bookworm)
fedoraprojectfedora
msrcazl3_unzip_6.0-21_on_azure_linux_3.0
msrcazl3_unzip_6.0-22_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_unzip_6.0-21_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_unzip_6.0-19_on_cbl_mariner_1.0
redhatenterprise_linux
unzip_projectunzip
unzip_projectunzip>= 0 < 6.0-26+deb11u16.0-26+deb11u1
unzip_projectunzip>= 0 < 6.0-276.0-27
unzip_projectunzip>= 0 < 6.0-276.0-27
unzip_projectunzip>= 0 < 6.0-276.0-27

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM