Moderate CentOS unzip Security Update

Metadata

medium
5.0
unzip-6.0-15.el7.src.rpm, unzip-6.0-15.el7.x86_64.rpm, unzip-6.0-2.el6_6.i686.rpm, unzip-6.0-2.el6_6.src.rpm, unzip-6.0-2.el6_6.x86_64.rpm
CVE-2014-8139, CVE-2014-8140, CVE-2014-8141, CVE-2014-9636
rhn.redhat.com, lists.centos.org, lists.centos.org
2015-04-01
2017-07-27 19:08
ALAS-2015-504
CVE-2014-8140 unzip
CVE-2014-8139 unzip
CVE-2014-8141 unzip
CVE-2014-9636 unzip
CVE-2014-8140
CVE-2014-8139
CVE-2014-9636
CVE-2014-8141
2017-04-01 19:08
2017-01-05 20:13

Description


Updated unzip packages that fix multiple security issues are now available
for Red Hat Enterprise Linux 6 and 7.

Red Hat Product Security has rated this update as having Moderate security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.

The unzip utility is used to list, test, or extract files from a
zip archive.

A buffer overflow was found in the way unzip uncompressed certain extra
fields of a file. A specially crafted Zip archive could cause unzip to
crash or, possibly, execute arbitrary code when the archive was tested with
unzip's '-t' option. (CVE-2014-9636)

A buffer overflow flaw was found in the way unzip computed the CRC32
checksum of certain extra fields of a file. A specially crafted Zip archive
could cause unzip to crash when the archive was tested with unzip's '-t'
option. (CVE-2014-8139)

An integer underflow flaw, leading to a buffer overflow, was found in the
way unzip uncompressed certain extra fields of a file. A specially crafted
Zip archive could cause unzip to crash when the archive was tested with
unzip's '-t' option. (CVE-2014-8140)

A buffer overflow flaw was found in the way unzip handled Zip64 files.
A specially crafted Zip archive could possibly cause unzip to crash when
the archive was uncompressed. (CVE-2014-8141)

Red Hat would like to thank oCERT for reporting the CVE-2014-8139,
CVE-2014-8140, and CVE-2014-8141 issues. oCERT acknowledges Michele
Spagnuolo of the Google Security Team as the original reporter of
these issues.

All unzip users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.
Please see https://www.redhat.com/footer/terms-of-use.html

Am I vulnerable?

The constraints below list the versions that this vulnerability is patched in, and versions that are unaffected. If a patch is ready but unrealeased, then it is pending.

Or, you can just let us figure it out for you! Appcanary continously monitor your installed packages, and tell you if any of them are vulnerable.

Sign up for monitoring

Affected package information

Release Package Patched in
6 unzip unzip-6.0-2.el6_6.i686.rpm
unzip unzip-6.0-2.el6_6.src.rpm
unzip unzip-6.0-2.el6_6.x86_64.rpm
7 unzip unzip-6.0-15.el7.src.rpm
unzip unzip-6.0-15.el7.x86_64.rpm