FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-04-23 14:57:51 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
3680b234-b6f0-11e4-b7cc-d050992ecde8unzip -- heap based buffer overflow in iconv patch

Ubuntu Security Notice USN-2502-1 reports:

unzip could be made to run programs if it opened a specially crafted file.


Discovery 2015-02-17
Entry 2015-02-17
unzip
< 6.0_5

CVE-2015-1315
http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-1315.html
https://security-tracker.debian.org/tracker/CVE-2015-1315
http://www.ubuntu.com/usn/usn-2502-1/
86c3c66e-b2f5-11e5-863a-b499baebfeafunzip -- multiple vulnerabilities

Gustavo Grieco reports:

Two issues were found in unzip 6.0:

* A heap overflow triggered by unzipping a file with password (e.g unzip -p -P x sigsegv.zip).

* A denegation of service with a file that never finishes unzipping (e.g. unzip sigxcpu.zip).


Discovery 2015-09-26
Entry 2016-01-04
unzip
< 6.0_7

http://www.openwall.com/lists/oss-security/2015/09/07/4
ports/204413
CVE-2015-7696
CVE-2015-7697