PT-2018-3009 · Info Zip+3 · Unzip+3
Publicado
2018-02-09
·
Atualizado
2024-06-15
·
CVE-2018-1000035
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Info-Zip UnZip versions prior to 6.00
Description
A heap-based buffer overflow issue exists in the processing of password-protected archives, allowing an attacker to perform a denial of service or possibly achieve code execution. The vulnerability can be exploited by a remote attacker to cause a disruption in service.
Recommendations
For versions prior to 6.00, update to version 6.00 or later to resolve the issue. As a temporary workaround, consider avoiding the use of password-protected archives until a patch is available. Restrict access to the archive processing functionality to minimize the risk of exploitation.
Correção
DoS
Buffer Overflow
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Suse
Ubuntu
Unzip