Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: unzip

Found 4 matching suggestions

View:
Compact
Detailed
Dismissed
updated 1 month ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    5 packages
    • runzip
    • ripunzip
    • unzipNLS
    • haskellPackages.unzip-traversable
    • haskellPackages.wai-middleware-gunzip
  • @LeSuisse dismissed
The NEEDBITS macro in the inflate_dynamic function in inflate.c for …

The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.

References

Affected products

n/a
  • ==n/a
unzip
  • <6.0

Matching in nixpkgs

pkgs.unzip

Extraction utility for archives compressed in .zip format

  • nixos-unstable -
Ignored packages (5)

pkgs.runzip

Tool to convert filename encoding inside a ZIP archive

  • nixos-unstable -

pkgs.ripunzip

Tool to unzip files in parallel

  • nixos-unstable -

pkgs.unzipNLS

Extraction utility for archives compressed in .zip format

  • nixos-unstable -

Package maintainers

Current stable branch was never impacted

https://github.com/NixOS/nixpkgs/commit/672d3856df5d0e0e5bd5053e59cd5925b85e9f4a
Dismissed
updated 1 month ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    5 packages
    • ripunzip
    • unzipNLS
    • haskellPackages.unzip-traversable
    • haskellPackages.wai-middleware-gunzip
    • runzip
  • @LeSuisse dismissed
Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip …

Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

Affected products

UnZip
  • ==6.0 and earlier

Matching in nixpkgs

pkgs.unzip

Extraction utility for archives compressed in .zip format

Ignored packages (5)

pkgs.runzip

Tool to convert filename encoding inside a ZIP archive

pkgs.unzipNLS

Extraction utility for archives compressed in .zip format

Package maintainers

Current stable branch was never impacted

https://github.com/NixOS/nixpkgs/commit/173f41cf0bc618f0b2c313b1915fee8d8a6d0ee2
Dismissed
updated 1 month ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    5 packages
    • runzip
    • ripunzip
    • unzipNLS
    • haskellPackages.unzip-traversable
    • haskellPackages.wai-middleware-gunzip
  • @LeSuisse dismissed
Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip …

Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

Affected products

UnZip
  • ==6.0 and earlier

Matching in nixpkgs

pkgs.unzip

Extraction utility for archives compressed in .zip format

Ignored packages (5)

pkgs.runzip

Tool to convert filename encoding inside a ZIP archive

pkgs.unzipNLS

Extraction utility for archives compressed in .zip format

Package maintainers

Current stable branch was never impacted

https://github.com/NixOS/nixpkgs/commit/173f41cf0bc618f0b2c313b1915fee8d8a6d0ee2
Dismissed
updated 1 month ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    5 packages
    • runzip
    • ripunzip
    • unzipNLS
    • haskellPackages.unzip-traversable
    • haskellPackages.wai-middleware-gunzip
  • @LeSuisse dismissed
Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip …

Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

Affected products

UnZip
  • ==6.0 and earlier

Matching in nixpkgs

pkgs.unzip

Extraction utility for archives compressed in .zip format

Ignored packages (5)

pkgs.runzip

Tool to convert filename encoding inside a ZIP archive

pkgs.unzipNLS

Extraction utility for archives compressed in .zip format

Package maintainers

Current stable branch was never impacted

https://github.com/NixOS/nixpkgs/commit/173f41cf0bc618f0b2c313b1915fee8d8a6d0ee2