FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2015-7697

This CVE name corresponds to:

Entered Topic
2016-01-04 unzip -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2015-7697
Phase Assigned(20151004)

Description

Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (infinite loop) via empty bzip2 data in a ZIP archive.

References

Source Reference
MLIST [oss-security] 20150907 Heap overflow and DoS in unzip 6.0
MLIST [oss-security] 20150915 Re: Heap overflow and DoS in unzip 6.0
MLIST [oss-security] 20151011 Re: Heap overflow and DoS in unzip 6.0
MISC http://sourceforge.net/p/infozip/patches/23/
DEBIAN DSA-3386
UBUNTU USN-2788-1
BID 76863
SECTRACK 1034027