CVE-2022-0530
⚪ Do wiadomości
Błąd w Unzip umożliwia zdalne wykonanie kodu przez specjalnie przygotowany plik zip.
CVSS
5.5
EPSS
2.1%
Exploit
poc
Vendor
apple
Opis źródłowy (NVD)
A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 2.1% |
| Opublikowano (NVD) | 2022-02-09 23:15:16 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 21:17:43 UTC |
Referencje
- http://seclists.org/fulldisclosure/2022/May/33 ([email protected]) [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2022/May/35 ([email protected]) [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2022/May/38 ([email protected]) [Mailing List, Third Party Advisory]
- https://bugzilla.redhat.com/show_bug.cgi?id=2051395 ([email protected]) [Issue Tracking, Third Party Advisory]
- https://github.com/ByteHackr/unzip_poc ([email protected]) [Exploit, Third Party Advisory]
- https://lists.debian.org/debian-lts-announce/2022/09/msg00028.html ([email protected]) [Mailing List, Third Party Advisory]
- https://security.gentoo.org/glsa/202310-17 ([email protected]) [Third Party Advisory]
- https://support.apple.com/kb/HT213255 ([email protected]) [Vendor Advisory]
- https://support.apple.com/kb/HT213256 ([email protected]) [Vendor Advisory]
- https://support.apple.com/kb/HT213257 ([email protected]) [Vendor Advisory]
- https://www.debian.org/security/2022/dsa-5202 ([email protected]) [Third Party Advisory]