Logo
vulnerabilityCVE-2014-8141
Name
CVE-2014-8141
Source
NVD ( link)Debian ( link)
Description
Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
unzip
Patched

Vulnerability Ratings#


7.8
CVSSv31
6.8
CVSSv2

Others affected component#


Name
Project
Project Version
Version
Status
openwrt
master
6.0-r9
Patched

Resolved with patches#


unzip (openwrt:master)

#
Title
Author
Resolve
1
fix: heap-based buffer overflow in the getZip64Data
OpenWrt community <openwrt-devel@lists.openwrt.org>
CVE-2014-8141

unzip (openwrt:openwrt-25.12)

#
Title
Author
Resolve
1
fix: heap-based buffer overflow in the getZip64Data
OpenWrt community <openwrt-devel@lists.openwrt.org>
CVE-2014-8141