PT-2016-3239 · Info Zip+3 · Info-Zip Unzip+3

Alexis

+1

·

Publicado

2016-11-03

·

Atualizado

2024-06-15

·

CVE-2016-9844

CVSS v3.1

4.0

Média

VetorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Info-Zip Unzip version 6.0
Description The issue is caused by a buffer overflow in the zi short function, located in the zipinfo.c file of the Info-Zip Unzip file archiver. This buffer overflow occurs due to an out-of-bounds operation in memory. The exploitation of this issue may allow a remote attacker to cause a denial of service, specifically a crash, through vectors related to the compression method. This can be achieved by using a large compression method value in the central directory file header.
Recommendations For Info-Zip Unzip version 6.0, consider applying a patch or update that fixes the buffer overflow in the zi short function to prevent potential denial of service attacks. As a temporary workaround, restrict the use of large compression method values in the central directory file header to minimize the risk of exploitation.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2020-3276
ALT-PU-2020-3281
ALT-PU-2020-3294
AZL-35338
AZL-6940
BDU:2018-00031
BDU:2018-00032
CVE-2016-9844
DLA-741-1
MGASA-2017-0015
OPENSUSE-SU-2018_3043-1
OPENSUSE-SU-2024:11485-1
SUSE-SU-2017:0639-1
SUSE-SU-2018:2978-1
USN-4672-1

Produtos afetados

Alt Linux
Info-Zip Unzip
Suse
Ubuntu