CVE-2015-7696

Name
CVE-2015-7696
Description
Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly execute arbitrary code via a crafted password-protected ZIP archive, possibly related to an Extra-Field size value.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MLIST http://www.openwall.com/lists/oss-security/2015/09/21/6
SECTRACK http://www.securitytracker.com/id/1034027
DEBIAN http://www.debian.org/security/2015/dsa-3386
MLIST http://www.openwall.com/lists/oss-security/2015/09/15/6
BID http://www.securityfocus.com/bid/76863
MLIST http://www.openwall.com/lists/oss-security/2015/09/07/4
MLIST http://www.openwall.com/lists/oss-security/2015/10/11/5
UBUNTU http://www.ubuntu.com/usn/USN-2788-1
UBUNTU http://www.ubuntu.com/usn/USN-2788-2

Match rules

CPE URI Source package Min version Max version
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* ubuntu_linux == None == 14.04
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:* ubuntu_linux == None == 12.04
cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:* ubuntu_linux == None == 15.10
cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:* ubuntu_linux == None == 15.04
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* debian_linux == None == 7.0
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* debian_linux == None == 8.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status