First published: Wed Jan 18 2017(Updated: )
Buffer overflow in the zi_short function in zipinfo.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via a large compression method value in the central directory file header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
unzip | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9844 has been classified with a moderate severity level due to its potential to cause a denial of service.
To fix CVE-2016-9844, users should upgrade to a patched version of UnZip that addresses the buffer overflow vulnerability.
The potential impacts of CVE-2016-9844 include application crashes and denial of service due to the exploitation of the buffer overflow.
CVE-2016-9844 affects users of Info-Zip UnZip version 6.0, particularly those processing ZIP files with large compression method values.
CVE-2016-9844 exploits a buffer overflow in the zi_short function, allowing attackers to manipulate the central directory file header.