CVE Database
/

CVE-2014-8140

Back to search

CVE-2014-8140

Published: Jan 31, 2020

Modified: Aug 6, 2024

PUBLISHED

Description

Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

VendorProductVersions

Info-ZIP

UnZip

affected
6.0 and earlier

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now