CVE Database
/

CVE-2014-9636

Back to search

CVE-2014-9636

Published: Feb 6, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra field with an uncompressed size smaller than the compressed field size in a zip archive that advertises STORED method compression.

VendorProductVersions

n/a

n/a

affected
n/a

References

62738
third-party-advisory
x_refsource_SECUNIA
GLSA-201611-01
vendor-advisory
x_refsource_GENTOO
FEDORA-2015-1267
vendor-advisory
x_refsource_FEDORA
62751
third-party-advisory
x_refsource_SECUNIA
71825
vdb-entry
x_refsource_BID
USN-2489-1
vendor-advisory
x_refsource_UBUNTU
DSA-3152
vendor-advisory
x_refsource_DEBIAN
[oss-security] 20141102 unzip -t crasher
mailing-list
x_refsource_MLIST
FEDORA-2015-1189
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now