CVE-2015-1315

Publication date 17 February 2015

Last updated 24 July 2024


Ubuntu priority

Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote attackers to execute arbitrary code via a crafted string, as demonstrated by converting a string from CP866 to UTF-8.

Status

Package Ubuntu Release Status
unzip 14.10 utopic
Fixed 6.0-12ubuntu1.3
14.04 LTS trusty
Fixed 6.0-9ubuntu1.3
12.04 LTS precise
Fixed 6.0-4ubuntu2.3
10.04 LTS lucid
Not affected

References

Related Ubuntu Security Notices (USN)

    • USN-2502-1
    • unzip vulnerabilities
    • 17 February 2015

Other references