CVE-2015-7696
unzip - security update
EPSS 34.9%
Description
Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly execute arbitrary code via a crafted password-protected ZIP archive, possibly related to an Extra-Field size value.
How to fix CVE-2015-7696
To remediate CVE-2015-7696, upgrade the affected package to a fixed version below.
- Alpine/unzip—upgrade to 6.0-r1 or later
- Debian/unzip—upgrade to 6.0-19 or later
- Debian/unzip—upgrade to 6.0-4+deb6u3 or later
- —upgrade to 6.0-8+deb7u4 or later
Is CVE-2015-7696 being exploited?
Moderate — EPSS is 34.9%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (4)
- from 0, < 6.0-r1
- from 0, < 6.0-19
- from 0, < 6.0-4+deb6u3
- from 0, < 6.0-8+deb7u4