QID 671101
Date Published: 2021-11-29
QID 671101: EulerOS Security Update for unzip (EulerOS-SA-2019-2234)
The unzip utility is used to list, test, or extract files from a zip archive.
Zip archives are commonly found on ms-dos systems.
The zip utility, included in the zip package, creates zip archives.
Zip and unzip are both compatible with archives created by pkware(r)'s pkzip for ms-dos, but the programs' options and default behaviors do differ in some respects.
Install the unzip package if you need to list, test or extract files from a zip archive.
Security fix(es): info-zip unzip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly execute arbitrary code via a crafted password-protected zip archive, possibly related to an extra-field size value.(cve-2015-7696) info-zip unzip 6.0 allows remote attackers to cause a denial of service (infinite loop) via empty bzip2 data in a zip archive.(cve-2015-7697)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
An arbitrary attacker may exploit this vulnerability to compromise the system.
CVEs related to QID 671101
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| EulerOS-SA-2019-2234 | EulerOS V2.0SP5 |
|