CVE-2025-15649: IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date
IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libio-compress-perlto a version that resolves this vulnerability.Fixed in 2.223-1 - Upgrade
Upgrade
debian/perlto a version that resolves this vulnerability.Fixed in 5.42.3-1 - Upgrade
Upgrade
IO::Uncompress::Unzip (Perl)to a version that resolves this vulnerability.Fixed in 2.215
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15649?
CVE-2025-15649 is rated with a risk score of 30.
How do I fix CVE-2025-15649?
To remediate CVE-2025-15649, upgrade to IO-Compress version 2.215 or later.
What software is affected by CVE-2025-15649?
CVE-2025-15649 affects the IO::Uncompress::Unzip module for Perl.
What issue does CVE-2025-15649 cause?
CVE-2025-15649 causes uncaught exceptions when parsing zip headers with malformed DOS dates.
When was CVE-2025-15649 published?
CVE-2025-15649 was published on May 27, 2026.