CVE-2022-0530
Summary
| CVE | CVE-2022-0530 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-09 23:15:00 UTC |
| Updated | 2023-11-09 20:55:00 UTC |
| Description | A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Macos | All | All | All | All |
| Operating System | Apple | Mac Os X | All | All | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | - | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2020 | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2020-001 | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2020-005 | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2020-007 | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2021-001 | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2021-002 | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2021-003 | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2021-006 | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2021-007 | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2021-008 | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2022-001 | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2022-002 | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2022-003 | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | supplemental_update | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 35 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 8.0 | All | All | All |
| Application | Unzip Project | Unzip | 6.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| About the security content of macOS Big Sur 11.6.6 - Apple Support | CONFIRM | support.apple.com | |
| Full Disclosure: APPLE-SA-2022-05-16-2 macOS Monterey 12.4 | FULLDISC | seclists.org | |
| About the security content of macOS Monterey 12.4 - Apple Support | CONFIRM | support.apple.com | |
| GitHub - ByteHackr/unzip_poc: CVE-2022-0529 & CVE-2022-0530 | MISC | github.com | |
| About the security content of Security Update 2022-004 Catalina - Apple Support | CONFIRM | support.apple.com | |
| UnZip: Multiple Vulnerabilities (GLSA 202310-17) — Gentoo security | MISC | security.gentoo.org | |
| Debian -- Security Information -- DSA-5202-1 unzip | DEBIAN | www.debian.org | |
| [SECURITY] [DLA 3118-1] unzip security update | MLIST | lists.debian.org | |
| Full Disclosure: APPLE-SA-2022-05-16-3 macOS Big Sur 11.6.6 | FULLDISC | seclists.org | |
| 2051395 – (CVE-2022-0530) CVE-2022-0530 unzip: SIGSEGV during the conversion of an utf-8 string to a local string | MISC | bugzilla.redhat.com | |
| Full Disclosure: APPLE-SA-2022-05-16-4 Security Update 2022-004 Catalina | FULLDISC | seclists.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 180923 Debian Security Update for unzip (DSA 5202-1)
- 181070 Debian Security Update for unzip (DLA 3118-1)
- 184276 Debian Security Update for unzip (CVE-2022-0530)
- 198984 Ubuntu Security Notification for unzip Vulnerabilities (USN-5673-1)
- 354477 Amazon Linux Security Advisory for unzip : ALAS2022-2022-221
- 354574 Amazon Linux Security Advisory for unzip : ALAS-2022-221
- 354660 Amazon Linux Security Advisory for unzip : ALAS2-2023-1906
- 355191 Amazon Linux Security Advisory for unzip : ALAS2023-2023-029
- 376607 Apple macOS Security Update 2022-004 Catalina (HT213255)
- 376608 Apple MacOS Big Sur 11.6.6 Not Installed (HT213256)
- 376612 Apple macOS Monterey 12.4 Not Installed (HT213257)
- 502799 Alpine Linux Security Update for unzip
- 671636 EulerOS Security Update for unzip (EulerOS-SA-2022-1653)
- 671637 EulerOS Security Update for unzip (EulerOS-SA-2022-1667)
- 671721 EulerOS Security Update for unzip (EulerOS-SA-2022-1768)
- 671799 EulerOS Security Update for unzip (EulerOS-SA-2022-1854)
- 671824 EulerOS Security Update for unzip (EulerOS-SA-2022-1878)
- 671827 EulerOS Security Update for unzip (EulerOS-SA-2022-1917)
- 710777 Gentoo Linux UnZip Multiple Vulnerabilities (GLSA 202310-17)
- 752613 SUSE Enterprise Linux Security Update for unzip (SUSE-SU-2022:3386-1)
- 752621 SUSE Enterprise Linux Security Update for unzip (SUSE-SU-2022:3399-1)
- 900678 Common Base Linux Mariner (CBL-Mariner) Security Update for unzip (8545)
- 901412 Common Base Linux Mariner (CBL-Mariner) Security Update for unzip (8533)