Logo
vulnerabilityCVE-2014-8139
Name
CVE-2014-8139
Source
NVD ( link)Debian ( link)
Description
Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
unzip
Patched

Vulnerability Ratings#


7.8
CVSSv31
6.8
CVSSv2

Others affected component#


Name
Project
Project Version
Version
Status
openwrt
openwrt-25.12
6.0-r9
Patched

Resolved with patches#


unzip (openwrt:master)

#
Title
Author
Resolve
1
fix: heap-based buffer overflow in the CRC32
OpenWrt community <openwrt-devel@lists.openwrt.org>
CVE-2014-8139

unzip (openwrt:openwrt-25.12)

#
Title
Author
Resolve
1
fix: heap-based buffer overflow in the CRC32
OpenWrt community <openwrt-devel@lists.openwrt.org>
CVE-2014-8139