Unrated severityNVD Advisory· Published Jan 31, 2020· Updated Aug 6, 2024
CVE-2014-8139
CVE-2014-8139
Description
Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.ocert.org/advisories/ocert-2014-011.htmlmitrex_refsource_MISC
- www.securitytracker.com/id/1031433mitrex_refsource_MISC
- access.redhat.com/errata/RHSA-2015:0700mitrex_refsource_MISC
- bugzilla.redhat.com/show_bug.cgimitrex_refsource_MISC
News mentions
0No linked articles in our index yet.