It was discovered that "unzip -l" (CVE-2014-9913) and "zipinfo" (CVE-2016-9844) were vulnerable to buffer overflows when provided malformed or maliciously-crafted ZIP files.
{ "section": "core" }