CVE-2016-9844: Buffer Overflow
Buffer overflow in the zishort function in zipinfo.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via a large compression method value in the central directory file header.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9844?
CVE-2016-9844 has been classified with a moderate severity level due to its potential to cause a denial of service.
How do I fix CVE-2016-9844?
To fix CVE-2016-9844, users should upgrade to a patched version of UnZip that addresses the buffer overflow vulnerability.
What are the potential impacts of CVE-2016-9844?
The potential impacts of CVE-2016-9844 include application crashes and denial of service due to the exploitation of the buffer overflow.
Who is affected by CVE-2016-9844?
CVE-2016-9844 affects users of Info-Zip UnZip version 6.0, particularly those processing ZIP files with large compression method values.
How does CVE-2016-9844 exploit a buffer overflow?
CVE-2016-9844 exploits a buffer overflow in the zi_short function, allowing attackers to manipulate the central directory file header.