PT-2016-3239 · Info Zip+3 · Info-Zip Unzip+3

Alexis

+1

·

Published

2016-11-03

·

Updated

2024-06-15

·

CVE-2016-9844

CVSS v3.1

4.0

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Info-Zip Unzip version 6.0
Description The issue is caused by a buffer overflow in the zi short function, located in the zipinfo.c file of the Info-Zip Unzip file archiver. This buffer overflow occurs due to an out-of-bounds operation in memory. The exploitation of this issue may allow a remote attacker to cause a denial of service, specifically a crash, through vectors related to the compression method. This can be achieved by using a large compression method value in the central directory file header.
Recommendations For Info-Zip Unzip version 6.0, consider applying a patch or update that fixes the buffer overflow in the zi short function to prevent potential denial of service attacks. As a temporary workaround, restrict the use of large compression method values in the central directory file header to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3276
ALT-PU-2020-3281
ALT-PU-2020-3294
AZL-35338
AZL-6940
BDU:2018-00031
BDU:2018-00032
CVE-2016-9844
DLA-741-1
MGASA-2017-0015
OPENSUSE-SU-2018_3043-1
OPENSUSE-SU-2024:11485-1
SUSE-SU-2017:0639-1
SUSE-SU-2018:2978-1
USN-4672-1

Affected Products

Alt Linux
Info-Zip Unzip
Suse
Ubuntu