CVE-2018-18384 describes a buffer overflow vulnerability in Info-ZIP UnZip 6.0, specifically within the list.c component. This flaw arises when processing specially crafted ZIP archives where the compressed and uncompressed size values are manipulated, leading to an insufficient buffer size. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring user interaction. A successful exploit could lead to high availability impact, potentially causing a denial of service. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0CPE matchmatch criteria | cpe:2.3:a:unzip_project:unzip:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2018-18384
Jun 11, 2024CVE-2018-18384
Aug 11, 2020Info-ZIP UnZip 6.0 has a buffer overflow in list.c when a ZIP archive has a crafted relationship between the compressed-size value and the uncompressed-size value because a buffer size is 10 and is supposed to be 12.
Oct 9, 2018unzip: Buffer overflow in list.c resulting in a denial of service
Sep 28, 2018