AVG-611 log

Package unzip
Status Fixed
Severity Medium
Type multiple issues
Affected 6.0-14
Fixed 6.0-15
Current 6.0-20 [extra]
Ticket None
Created Mon Feb 12 23:01:13 2018
Issue Severity Remote Type Description
CVE-2019-13232 Low Yes Denial of service
Info-ZIP UnZip 6.0 mishandles the overlapping of files inside a ZIP container, leading to denial of service (resource consumption), aka a "better zip bomb" issue.
CVE-2018-1000035 Low No Arbitrary code execution
A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a...
CVE-2018-18384 Medium Yes Arbitrary code execution
Info-ZIP UnZip 6.0 has a buffer overflow in list.c, when a ZIP archive has a crafted relationship between the compressed-size value and the...
CVE-2016-9844 Low Yes Denial of service
A buffer overflow in the zi_short function in zipinfo.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via a large...
CVE-2014-9913 Low Yes Denial of service
A buffer overflow in the list_files function in list.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via vectors...