CVE-2014-9913: Buffer Overflow
Published Jan 18, 2017
·Updated
Buffer overflow in the listfiles function in list.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via vectors related to the compression method.
Affected Software
15 affected componentsFixes available
Unzip Project Unzip=6.0
Microsoft unzip-6.0-19.cm2.aarch64.rpm
Microsoft azl3 unzip 6.0-22
Microsoft cbl2 unzip 6.0-19
Microsoft cm1 unzip 6.0-15
Microsoft unzip-6.0-20.azl3.x86_64.rpm
Microsoft azl3 unzip 6.0-20
Microsoft unzip-6.0-19.cm2.x86_64.rpm
Microsoft unzip-debuginfo-6.0-19.cm2.x86_64.rpm
Microsoft unzip-6.0-20.azl3.aarch64.rpm
Microsoft unzip-6.0-15.cm1.aarch64.rpm
Microsoft unzip-debuginfo-6.0-15.cm1.aarch64.rpm
Microsoft unzip-debuginfo-6.0-19.cm2.aarch64.rpm
Microsoft unzip-debuginfo-6.0-15.cm1.x86_64.rpm
Microsoft unzip-6.0-15.cm1.x86_64.rpm
Event History
Jan 18, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
DescriptionSeverityWeaknessAffected Software
Aug 18, 2020
Data Sourced
via Microsoft·12:00 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·12:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Updated
via Microsoft·07:00 AM
SeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-9913?
CVE-2014-9913 is classified as a denial of service vulnerability due to a buffer overflow that can cause crashes.
2
How do I fix CVE-2014-9913?
To mitigate CVE-2014-9913, upgrade to a patched version of UnZip that has addressed the buffer overflow issue.
3
What is affected by CVE-2014-9913?
CVE-2014-9913 specifically affects Info-Zip UnZip version 6.0.
4
Can CVE-2014-9913 be exploited remotely?
Yes, CVE-2014-9913 can be exploited remotely by attackers using specific compression method vectors.
5
What is the impact of CVE-2014-9913?
The impact of CVE-2014-9913 is a denial of service, resulting in a potential crash of the UnZip application.