{
  "threat_severity" : "Moderate",
  "public_date" : "2014-11-02T00:00:00Z",
  "bugzilla" : {
    "description" : "unzip: out-of-bounds read/write in test_compr_eb() in extract.c",
    "id" : "1184985",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1184985"
  },
  "cvss" : {
    "cvss_base_score" : "6.8",
    "cvss_scoring_vector" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
    "status" : "verified"
  },
  "cwe" : "CWE-20->CWE-122",
  "details" : [ "unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra field with an uncompressed size smaller than the compressed field size in a zip archive that advertises STORED method compression.", "A buffer overflow was found in the way unzip uncompressed certain extra fields of a file. A specially crafted Zip archive could cause unzip to crash or, possibly, execute arbitrary code when the archive was tested with unzip's '-t' option." ],
  "statement" : "Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates in Red Hat Enterprise Linux 5. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "release_date" : "2015-03-18T00:00:00Z",
    "advisory" : "RHSA-2015:0700",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6",
    "package" : "unzip-0:6.0-2.el6_6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2015-03-18T00:00:00Z",
    "advisory" : "RHSA-2015:0700",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "unzip-0:6.0-15.el7"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 5",
    "fix_state" : "Will not fix",
    "package_name" : "unzip",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2014-9636\nhttps://nvd.nist.gov/vuln/detail/CVE-2014-9636" ],
  "name" : "CVE-2014-9636",
  "csaw" : false
}