Back to Database
Status published
Low
CVE-2019-13232
Info-ZIP UnZip 6.0 mishandles the overlapping of files inside a...
Vulnerability Description
Info-ZIP UnZip 6.0 mishandles the overlapping of files inside a ZIP container, leading to denial of service (resource consumption), aka a "better zip bomb" issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-13232
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.bamsoftware.com/hacks/zipbomb/
- https://github.com/madler/unzip
- https://lists.debian.org/debian-lts-announce/2019/07/msg00005.html
- https://lists.debian.org/debian-lts-announce/2019/07/msg00027.html
- https://security.netapp.com/advisory/ntap-20190814-0002/
- https://support.f5.com/csp/article/K80311892?utm_source=f5support&%3Butm_medium=RSS
- https://security.gentoo.org/glsa/202003-58
More from unzip project
View All →CVE-2018-18384
Info-ZIP UnZip 6.0 has a buffer overflow in list.c, when...
Medium
5.5
CVE-2018-1000035
A heap-based buffer overflow exists in Info-Zip UnZip version <=...
High
7.8
CVE-2016-9844
Buffer overflow in the zi_short function in zipinfo.c in Info-Zip...
Medium
4
CVE-2014-9913
Buffer overflow in the list_files function in list.c in Info-Zip...
Medium
4
CVE-2014-9636
unzip 6.0 allows remote attackers to cause a denial of...
Medium
5
Affected Vendor
unzip project
View all reports →Affected Software
unzip, debian linux
Vulnerable Versions:
6.0, 8.0
Timeline
Official Publish:
July 4th, 2019
Last Modified:
August 4th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.