unzip -t crasher

2014.11.03
Credit: lcamtuf
Risk: Low
Local: Yes
Remote: No
CVE: N/A
CWE: N/A

Latest American fuzzy lop[0] tarball[1] contains a zip file that crashes unzip -t: $ unzip -qt afl-0.43b/docs/samples/unzip_t_malloc.zip foo/: mismatching "local" filename (/UT), continuing with "central" filename version *** Error in `unzip': free(): corrupted unsorted chunks: 0x00000000015d0170 *** I'm not sure if inclusion of said zip file was intentional, but since the cat is already out of the bag, I thought I'll let you know. [0] https://code.google.com/p/american-fuzzy-lop/ [1] http://lcamtuf.coredump.cx/afl.tgz

References:

http://lcamtuf.coredump.cx/afl.tgz
http://seclists.org/oss-sec/2014/q4/489


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top