Vulnerability Name:

CVE-2019-13232 (CCN-166873)

Assigned:2018-10-16
Published:2018-10-16
Updated:2020-06-16
Summary:Info-ZIP UnZip 6.0 mishandles the overlapping of files inside a ZIP container, leading to denial of service (resource consumption), aka a "better zip bomb" issue.
CVSS v3 Severity:3.3 Low (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L)
2.9 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
3.3 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)
2.9 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
4.0 Medium (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
3.5 Low (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
1.7 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-400
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2019-13232

Source: XF
Type: UNKNOWN
infozip-cve201913232-dos(166873)

Source: MISC
Type: Product, Release Notes, Third Party Advisory
https://github.com/madler/unzip

Source: CCN
Type: Info-ZIP Web site
Info-ZIP Home Page

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20190707 [SECURITY] [DLA 1846-1] unzip security update

Source: MLIST
Type: Third Party Advisory
[debian-lts-announce] 20190728 [SECURITY] [DLA 1846-2] unzip regression update

Source: GENTOO
Type: Third Party Advisory
GLSA-202003-58

Source: CCN
Type: NetApp Advisory Number NTAP-20190814-0002
CVE-2019-13232 Info-ZIP UnZip Vulnerability in NetApp Products

Source: CONFIRM
Type: Third Party Advisory
https://security.netapp.com/advisory/ntap-20190814-0002/

Source: CONFIRM
Type: Third Party Advisory
https://support.f5.com/csp/article/K80311892?utm_source=f5support&utm_medium=RSS

Source: MISC
Type: Third Party Advisory
https://www.bamsoftware.com/hacks/zipbomb/

Source: CCN
Type: IBM Security Bulletin 6198772 (MQ Appliance)
IBM MQ Appliance is affected by a denial of service vulnerability (CVE-2019-13232)

Source: CCN
Type: IBM Security Bulletin 6238168 (QRadar Network Security)
IBM QRadar Network Security is affected by multiple vulnerabilities

Source: CCN
Type: IBM Security Bulletin 6342859 (DataPower Gateway)
IBM DataPower Gateway may allow a potential DoS when importing malicious ZIP files (CVE-2019-13232)

Source: CCN
Type: IBM Security Bulletin 6347610 (QRadar SIEM)
Unzip as used by IBM QRadar SIEM is vulnerable to denial of service (CVE-2019-13232)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:unzip_project:unzip:6.0:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:debian:debian_linux:8.0:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:7::client:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:7::computenode:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:7::server:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:7::workstation:*:*:*:*:*

  • Configuration RedHat 6:
  • cpe:/o:redhat:enterprise_linux:8:*:*:*:*:*:*:*

  • Configuration RedHat 7:
  • cpe:/o:redhat:enterprise_linux:8::baseos:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:unzip_project:unzip:6.0:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:qradar_network_security:5.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:qradar_network_security:5.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:mq_appliance:9.1.0.0:*:*:*:continuous_delivery:*:*:*
  • OR cpe:/a:ibm:qradar_security_information_and_event_manager:7.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:datapower_gateway:2018.4.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:mq_appliance:9.1.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:mq_appliance:9.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:mq_appliance:9.1.0.2:*:*:*:continuous_delivery:*:*:*
  • OR cpe:/a:ibm:mq_appliance:9.1.2:*:*:*:continuous_delivery:*:*:*
  • OR cpe:/a:ibm:mq_appliance:9.1.0.3:*:*:*:continuous_delivery:*:*:*
  • OR cpe:/a:ibm:mq_appliance:9.1.3:*:*:*:continuous_delivery:*:*:*
  • OR cpe:/a:ibm:mq_appliance:9.1.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:mq_appliance:9.1.4:*:*:*:continuous_delivery:*:*:*
  • OR cpe:/a:ibm:mq_appliance:9.1.5:*:*:*:continuous_delivery:*:*:*
  • OR cpe:/a:ibm:datapower_gateway:2018.4.1.12:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:qradar_security_information_and_event_manager:7.4.0:-:*:*:*:*:*:*
  • OR cpe:/a:ibm:qradar_security_information_and_event_manager:7.4.1:-:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:com.redhat.rhsa:def:20201787
    P
    RHSA-2020:1787: unzip security update (Low)
    2020-04-28
    oval:com.redhat.rhsa:def:20201181
    P
    RHSA-2020:1181: unzip security update (Low)
    2020-03-31
    oval:com.ubuntu.cosmic:def:2019132320000000
    V
    CVE-2019-13232 on Ubuntu 18.10 (cosmic) - low.
    2019-07-08
    oval:com.ubuntu.bionic:def:2019132320000000
    V
    CVE-2019-13232 on Ubuntu 18.04 LTS (bionic) - low.
    2019-07-08
    oval:com.ubuntu.xenial:def:2019132320000000
    V
    CVE-2019-13232 on Ubuntu 16.04 LTS (xenial) - low.
    2019-07-08
    oval:com.ubuntu.disco:def:2019132320000000
    V
    CVE-2019-13232 on Ubuntu 19.04 (disco) - low.
    2019-07-04
    BACK
    unzip_project unzip 6.0
    debian debian linux 8.0
    info-zip unzip 6.0
    ibm qradar network security 5.4.0
    ibm qradar network security 5.5.0
    ibm mq appliance 9.1.0.0
    ibm qradar security information and event manager 7.3.0
    ibm datapower gateway 2018.4.1.0
    ibm mq appliance 9.1.0.1
    ibm mq appliance 9.1.1
    ibm mq appliance 9.1.0.2
    ibm mq appliance 9.1.2
    ibm mq appliance 9.1.0.3
    ibm mq appliance 9.1.3
    ibm mq appliance 9.1.0.4
    ibm mq appliance 9.1.4
    ibm mq appliance 9.1.5
    ibm datapower gateway 2018.4.1.12
    ibm qradar security information and event manager 7.4.0
    ibm qradar security information and event manager 7.4.1 -