PT-2016-3239 · Info Zip+3 · Info-Zip Unzip+3
Alexis
+1
·
Published
2016-11-03
·
Updated
2024-06-15
·
CVE-2016-9844
CVSS v3.1
4.0
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Info-Zip Unzip version 6.0
Description
The issue is caused by a buffer overflow in the
zi short function, located in the zipinfo.c file of the Info-Zip Unzip file archiver. This buffer overflow occurs due to an out-of-bounds operation in memory. The exploitation of this issue may allow a remote attacker to cause a denial of service, specifically a crash, through vectors related to the compression method. This can be achieved by using a large compression method value in the central directory file header.Recommendations
For Info-Zip Unzip version 6.0, consider applying a patch or update that fixes the buffer overflow in the
zi short function to prevent potential denial of service attacks. As a temporary workaround, restrict the use of large compression method values in the central directory file header to minimize the risk of exploitation.Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Info-Zip Unzip
Suse
Ubuntu