CVE-2019-13232: Low severity unzip vulnerability
Published Jul 4, 2019
·Updated
Info-ZIP UnZip 6.0 mishandles the overlapping of files inside a ZIP container, leading to denial of service (resource consumption), aka a "better zip bomb" issue.
Affected Software
2 affected components
Unzip Project Unzip=6.0
Debian Debian Linux=8.0
Event History
Jul 4, 2019
CVE Published
via MITRE·12:03 PM
Data Sourced
via MITRE·12:03 PM
Description
Frequently Asked Questions
1
What is CVE-2019-13232?
CVE-2019-13232 is a vulnerability in Info-ZIP UnZip 6.0 that mishandles the overlapping of files inside a ZIP container, leading to denial of service.
2
How does CVE-2019-13232 affect Info-ZIP UnZip 6.0?
CVE-2019-13232 affects Info-ZIP UnZip 6.0 by causing a denial of service due to resource consumption.
3
What is the severity level of CVE-2019-13232?
The severity of CVE-2019-13232 is low with a severity value of 3.3.
4
How can I fix CVE-2019-13232?
To fix CVE-2019-13232, update to a patched version of Info-ZIP UnZip 6.0 or a newer version.
5
Where can I find more information about CVE-2019-13232?
You can find more information about CVE-2019-13232 on the GitHub page for madler/unzip and the Debian security announcement.