REDHAT-BUG-1642931: Buffer Overflow
Info-ZIP UnZip 6.0 has a buffer overflow in list.c, when a ZIP archive has a crafted relationship between the compressed-size value and the uncompressed-size value, because a buffer size is 10 and is supposed to be 12.
References:
https://bugzilla.suse.com/showbug.cgi?id=1110194 https://sourceforge.net/p/infozip/bugs/53/ https://src.fedoraproject.org/rpms/unzip/blob/master/f/unzip-6.0-overflow-long-fsize.patch
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1642931?
The severity of REDHAT-BUG-1642931 is considered critical due to the potential for buffer overflow exploits.
How do I fix REDHAT-BUG-1642931?
The recommended fix for REDHAT-BUG-1642931 is to apply the latest security patch provided by Info-ZIP for UnZip.
What exploits are associated with REDHAT-BUG-1642931?
Exploits associated with REDHAT-BUG-1642931 can lead to arbitrary code execution through crafted ZIP files.
Which versions of Info-ZIP UnZip are affected by REDHAT-BUG-1642931?
Info-ZIP UnZip version 6.0 is specifically affected by REDHAT-BUG-1642931.
What are the potential impacts of REDHAT-BUG-1642931?
The potential impacts of REDHAT-BUG-1642931 include system crashes and compromised system integrity through arbitrary code execution.