CVE-2015-1315: Buffer Overflow
Buffer overflow in the charsettointern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote attackers to execute arbitrary code via a crafted string, as demonstrated by converting a string from CP866 to UTF-8.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1315?
CVE-2015-1315 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2015-1315?
To fix CVE-2015-1315, update to a patched version of Info-ZIP UnZip or apply available security updates for affected Ubuntu systems.
Which systems are affected by CVE-2015-1315?
CVE-2015-1315 affects Info-ZIP UnZip version 6.10b and specific versions of Ubuntu Linux including 12.04, 14.04, and 14.10.
What type of vulnerability is CVE-2015-1315?
CVE-2015-1315 is a buffer overflow vulnerability that allows remote attackers to execute arbitrary code.
Can CVE-2015-1315 be exploited remotely?
Yes, CVE-2015-1315 can be exploited remotely via crafted strings processed by the affected software.