yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2016-9844
Component Overview
Vulnerability Overview
Name
CVE-2016-9844
Source
NVD (
link
)
Debian (
link
)
Description
Buffer overflow in the zi_short function in zipinfo.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via a large compression method value in the central directory file header.
CWEs
CWE-119
Published Date
Jan 18, 2017
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://www.openwall.com/lists/oss-security/2016/12/05/13
Mailing List
http://www.openwall.com/lists/oss-security/2016/12/05/19
Mailing List
http://www.openwall.com/lists/oss-security/2016/12/05/20
Mailing List
http://www.securityfocus.com/bid/94728
VDB Entry
https://bugs.launchpad.net/ubuntu/+source/unzip/+bug/1643750
Issue Tracking
http://www.openwall.com/lists/oss-security/2016/12/05/13
Mailing List
http://www.openwall.com/lists/oss-security/2016/12/05/19
Mailing List
http://www.openwall.com/lists/oss-security/2016/12/05/20
Mailing List
http://www.securityfocus.com/bid/94728
VDB Entry
https://bugs.launchpad.net/ubuntu/+source/unzip/+bug/1643750
Issue Tracking
Analysis
#
Affected Component
Analysis
unzip
Patched
Vulnerability Ratings
#
4
other
2.1
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
unzip
buildroot
2025.02.x
6.0
Patched
unzip
buildroot
master
6.0
Patched
unzip
yocto
kirkstone
6.0
Patched
unzip
yocto
master
6.0
Patched
Resolved with patches
#
unzip (buildroot:2025.02.x)
#
Title
Author
Resolve
1
Fix CVE-2016-9844, buffer overflow in zipinfo
"Steven M. Schweda" <sms@antinode.info>
CVE-2016-9844
unzip (buildroot:master)
#
Title
Author
Resolve
1
Fix CVE-2016-9844, buffer overflow in zipinfo
"Steven M. Schweda" <sms@antinode.info>
CVE-2016-9844
unzip (yocto:kirkstone)
#
Title
Author
Resolve
1
Fix CVE-2016-9844, buffer overflow in zipinfo
"Steven M. Schweda" <sms@antinode.info>
CVE-2016-9844
unzip (yocto:master)
#
Title
Author
Resolve
1
Fix CVE-2016-9844, buffer overflow in zipinfo
"Steven M. Schweda" <sms@antinode.info>
CVE-2016-9844
unzip (yocto:scarthgap)
#
Title
Author
Resolve
1
Fix CVE-2016-9844, buffer overflow in zipinfo
"Steven M. Schweda" <sms@antinode.info>
CVE-2016-9844