Bug 1196180 - (CVE-2022-0529) VUL-0: CVE-2022-0529: unzip: Heap out-of-bound writes and reads during conversion of wide string to local string
(CVE-2022-0529)
VUL-0: CVE-2022-0529: unzip: Heap out-of-bound writes and reads during conver...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/322963/
CVSSv3.1:SUSE:CVE-2022-0529:4.7:(AV:L...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-02-18 16:06 UTC by Gabriele Sonnu
Modified: 2022-10-15 14:36 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---
gabriele.sonnu: needinfo? (danilo.spinella)


Attachments
debian patch (1.12 KB, patch)
2022-09-20 14:06 UTC, Gabriele Sonnu
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Gabriele Sonnu 2022-02-18 16:08:22 UTC
I was able to reproduce it on:

 - SUSE:SLE-12:Update/unzip       6.00
 - SUSE:SLE-15:Update/unzip       6.00
 - openSUSE:Factory/unzip         6.00

Not sure about:

 - SUSE:SLE-11-SP1:Update/unzip   5.52
 - SUSE:SLE-11-SP2:Update/unzip   6.00

I'd say they are affected too but please double check.
No patch available for now.
Comment 3 Gabriele Sonnu 2022-09-20 14:06:20 UTC
Created attachment 861574 [details]
debian patch

Added Debian patch, from [0]. Reproducers can be found in [1].

[0] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1010355
[1] https://github.com/ByteHackr/unzip_poc
Comment 6 Andreas Stieger 2022-09-26 15:40:08 UTC
Fix missing in unzip-rcc, pre-checkin was not run. Should be singlespec!


-# PATCH-FIX-UPSTREAM danilo.spinella@suse.com CVE-2022-0530 bsc#1196177
-Patch24:        CVE-2022-0530.patch
-# PATCH-FIX-UPSTREAM danilo.spinella@suse.com CVE-2022-0529 bsc#1196180
-Patch25:        CVE-2022-0529.patch

-%patch24 -p1
-%patch25 -p1
Comment 7 Swamp Workflow Management 2022-09-26 16:28:55 UTC
SUSE-SU-2022:3386-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1196177,1196180
CVE References: CVE-2022-0529,CVE-2022-0530
JIRA References: 
Sources used:
SUSE Linux Enterprise Server 12-SP5 (src):    unzip-6.00-33.16.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Swamp Workflow Management 2022-09-26 19:26:34 UTC
SUSE-SU-2022:3399-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1196177,1196180
CVE References: CVE-2022-0529,CVE-2022-0530
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    unzip-6.00-150000.4.11.1
openSUSE Leap 15.3 (src):    unzip-6.00-150000.4.11.1
SUSE Linux Enterprise Module for Basesystem 15-SP4 (src):    unzip-6.00-150000.4.11.1
SUSE Linux Enterprise Module for Basesystem 15-SP3 (src):    unzip-6.00-150000.4.11.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.