openwrt ▾
›
openwrt-25.12 ▾
›
vulnerability
›
CVE-2016-9844
Component Overview
Vulnerability Overview
Name
CVE-2016-9844
Source
NVD (
link
)
Debian (
link
)
Description
Buffer overflow in the zi_short function in zipinfo.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via a large compression method value in the central directory file header.
CWEs
CWE-119
Published Date
Jan 18, 2017
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://www.openwall.com/lists/oss-security/2016/12/05/13
Mailing List
http://www.openwall.com/lists/oss-security/2016/12/05/19
Mailing List
http://www.openwall.com/lists/oss-security/2016/12/05/20
Mailing List
http://www.securityfocus.com/bid/94728
VDB Entry
https://bugs.launchpad.net/ubuntu/+source/unzip/+bug/1643750
Issue Tracking
http://www.openwall.com/lists/oss-security/2016/12/05/13
Mailing List
http://www.openwall.com/lists/oss-security/2016/12/05/19
Mailing List
http://www.openwall.com/lists/oss-security/2016/12/05/20
Mailing List
http://www.securityfocus.com/bid/94728
VDB Entry
https://bugs.launchpad.net/ubuntu/+source/unzip/+bug/1643750
Issue Tracking
Analysis
#
Affected Component
Analysis
unzip
Patched
Vulnerability Ratings
#
4
other
2.1
CVSSv2
Others affected component
#
Name
Project
Project Version
Version
Status
unzip
openwrt
master
6.0-r9
Patched
Resolved with patches
#
unzip (openwrt:master)
#
Title
Author
Resolve
1
fix: buffer overflow in the zi_short function
OpenWrt community <openwrt-devel@lists.openwrt.org>
CVE-2016-9844
unzip (openwrt:openwrt-25.12)
#
Title
Author
Resolve
1
fix: buffer overflow in the zi_short function
OpenWrt community <openwrt-devel@lists.openwrt.org>
CVE-2016-9844