Untriaged
Activity log
- Created suggestion
The NEEDBITS macro in the inflate_dynamic function in inflate.c for …
The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.
References
Affected products
n/a
- ==n/a
unzip
- <6.0
Matching in nixpkgs
pkgs.unzip
Extraction utility for archives compressed in .zip format
pkgs.runzip
Tool to convert filename encoding inside a ZIP archive
pkgs.ripunzip
Tool to unzip files in parallel
pkgs.unzipNLS
Extraction utility for archives compressed in .zip format
pkgs.haskellPackages.unzip-traversable
Unzip functions for general Traversable containers
Package maintainers
-
@LeSuisse Thomas Gerbet <thomas@gerbet.me>
-
@7c6f434c Michael Raskin <7c6f434c@mail.ru>
-
@RossComputerGuy Tristan Ross <tristan.ross@midstall.com>