First published: Fri Feb 09 2018(Updated: )
A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a denial of service or to possibly achieve code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Unzip Project Unzip | <=6.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000035 is a heap-based buffer overflow vulnerability in Info-Zip UnZip version <= 6.00.
CVE-2018-1000035 has a severity rating of 7.8 (high).
Info-Zip UnZip versions up to and including 6.00 are affected by CVE-2018-1000035.
An attacker can perform a denial of service or possibly achieve code execution with CVE-2018-1000035.
Yes, you can find references related to CVE-2018-1000035 at the following URLs: [Reference 1](https://lists.debian.org/debian-lts-announce/2020/01/msg00026.html), [Reference 2](https://sec-consult.com/en/blog/advisories/multiple-vulnerabilities-in-infozip-unzip/index.html), [Reference 3](https://security.gentoo.org/glsa/202003-58).