Debian Zip vulnerabilities
2 known vulnerabilities affecting debian/zip.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1LOW1
Vulnerabilities
Page 1 of 1
CVE-2018-13410LOWCVSS 9.8fixed in zip 3.0-15 (forky)2018
CVE-2018-13410 [CRITICAL] CVE-2018-13410: zip - Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows atta...
Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact because of an off-by-one error. NOTE: it is unclear whether there are realistic scenarios in which an untrusted party controls the -TT value, given that the entire purpose of
debian
CVE-2004-1010CRITICALCVSS 10.0fixed in zip 2.30-8 (bookworm)2004
CVE-2004-1010 [CRITICAL] CVE-2004-1010: zip - Buffer overflow in Info-Zip 2.3 and possibly earlier versions, when using recurs...
Buffer overflow in Info-Zip 2.3 and possibly earlier versions, when using recursive folder compression, allows remote attackers to execute arbitrary code via a ZIP file containing a long pathname.
Scope: local
bookworm: resolved (fixed in 2.30-8)
bullseye: resolved (fixed in 2.30-8)
forky: resolved (fixed in 2.30-8)
sid: resolved (fixed in 2.30-8)
trixie: resolved (fi
debian