CVE-2022-0529
Summary
| CVE | CVE-2022-0529 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-09 23:15:00 UTC |
| Updated | 2023-11-09 20:55:00 UTC |
| Description | A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| GitHub - ByteHackr/unzip_poc: CVE-2022-0529 & CVE-2022-0530 |
MISC |
github.com |
|
| UnZip: Multiple Vulnerabilities (GLSA 202310-17) — Gentoo security |
MISC |
security.gentoo.org |
|
| 2051402 – (CVE-2022-0529) CVE-2022-0529 unzip: Heap out-of-bound writes and reads during conversion of wide string to local string |
MISC |
bugzilla.redhat.com |
|
| Debian -- Security Information -- DSA-5202-1 unzip |
DEBIAN |
www.debian.org |
|
| [SECURITY] [DLA 3118-1] unzip security update |
MLIST |
lists.debian.org |
|
| 2051395 – (CVE-2022-0530) CVE-2022-0530 unzip: SIGSEGV during the conversion of an utf-8 string to a local string |
MISC |
bugzilla.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 180923 Debian Security Update for unzip (DSA 5202-1)
- 181070 Debian Security Update for unzip (DLA 3118-1)
- 182933 Debian Security Update for unzip (CVE-2022-0529)
- 198984 Ubuntu Security Notification for unzip Vulnerabilities (USN-5673-1)
- 354477 Amazon Linux Security Advisory for unzip : ALAS2022-2022-221
- 354574 Amazon Linux Security Advisory for unzip : ALAS-2022-221
- 354660 Amazon Linux Security Advisory for unzip : ALAS2-2023-1906
- 355191 Amazon Linux Security Advisory for unzip : ALAS2023-2023-029
- 502799 Alpine Linux Security Update for unzip
- 671636 EulerOS Security Update for unzip (EulerOS-SA-2022-1653)
- 671637 EulerOS Security Update for unzip (EulerOS-SA-2022-1667)
- 671721 EulerOS Security Update for unzip (EulerOS-SA-2022-1768)
- 671799 EulerOS Security Update for unzip (EulerOS-SA-2022-1854)
- 671824 EulerOS Security Update for unzip (EulerOS-SA-2022-1878)
- 671827 EulerOS Security Update for unzip (EulerOS-SA-2022-1917)
- 710777 Gentoo Linux UnZip Multiple Vulnerabilities (GLSA 202310-17)
- 752613 SUSE Enterprise Linux Security Update for unzip (SUSE-SU-2022:3386-1)
- 752621 SUSE Enterprise Linux Security Update for unzip (SUSE-SU-2022:3399-1)
- 900677 Common Base Linux Mariner (CBL-Mariner) Security Update for unzip (8544)
- 901048 Common Base Linux Mariner (CBL-Mariner) Security Update for unzip (8532)