CVE-2022-0530
A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.
- Affected products
- Alt Linux, Astra Linux, Linuxmint, Apple Macos, Suse, Ubuntu, Unzip
- Unzip Project Unzip
- = 6.0
- CVSS 3.1
- 5.5 MEDIUM
- EPSS
- 2.1% (80th percentile)
- NVD status
- Modified
- Published
- 2022-02-09
CVE-2022-0530 at NVD
2 known exploits for CVE-2022-0530
Proof-of-concept code and exploit modules indexed by Sploitus