CVE-2022-0530
MEDIUMUnzip - Heap-Based Buffer Overflow via Wide String Conversion
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-0530. PoCs published by bytehackr.
AI-analyzed exploit summary This repository contains functional exploit scripts for CVE-2022-0530, demonstrating a segmentation fault vulnerability in unzip 6.0. The scripts use Docker to reproduce the issue with a malformed input file, leveraging valgrind for debugging.
Description
A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.
Exploits (1)
This repository contains functional exploit scripts for CVE-2022-0530, demonstrating a segmentation fault vulnerability in unzip 6.0. The scripts use Docker to reproduce the issue with a malformed input file, leveraging valgrind for debugging.
References (11)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H