CVE-2015-7696
Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly execute arbitrary code via a crafted password-protected ZIP archive, possibly related to an Extra-Field size value.
- Affected products
- Alt Linux, Info-Zip Unzip, Suse, Ubuntu
- Canonical Ubuntu Linux
- = 12.04, 14.04, 15.04, 15.10
- Debian Debian Linux
- = 7.0, 8.0
- CVSS 2.0
- 6.8 MEDIUM
- EPSS
- 7.2% (94th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2015-11-06
CVE-2015-7696 at NVD
1 known exploit for CVE-2015-7696
Proof-of-concept code and exploit modules indexed by Sploitus