huft_build in archival/libarchive/decompress_gunzip.c in...
Moderate severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Jul 26, 2018
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Jan 27, 2023
huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, causing segfaults and an application crash during an unzip operation on a specially crafted ZIP file.
References