Vulnerabilities
Vulnerable Software
Info-Zip:  >> Unzip  >> 5.50  Security Vulnerabilities
Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is invoked from other programs.
CVSS Score
3.7
EPSS Score
0.031
Published
2005-12-31
Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privileges.
CVSS Score
6.2
EPSS Score
0.0
Published
2005-05-02
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.
CVSS Score
2.6
EPSS Score
0.107
Published
2003-06-16


Contact Us

Shodan ® - All rights reserved