{"id":"CVE-2022-0530","title":"A flaw was found in Unzip","summary":"A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a cra…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","vendor":"unzip_project","product":"unzip","affected":["unzip = 6.0","enterprise_linux = 8.0","fedora = 35","mac_os_x >= 10.15, < 10.15.7","mac_os_x = 10.15.7","macos >= 11.0, < 11.6.6","macos >= 12.0.0, < 12.4","debian_linux = 10.0","debian_linux = 11.0"],"patched":["mac_os_x 10.15.7","macos 12.4"],"published":"2022-02-09","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:17:43.770","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-0530","references":[{"url":"http://seclists.org/fulldisclosure/2022/May/33","label":"secalert@redhat.com"},{"url":"http://seclists.org/fulldisclosure/2022/May/35","label":"secalert@redhat.com"},{"url":"http://seclists.org/fulldisclosure/2022/May/38","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2051395","label":"secalert@redhat.com"},{"url":"https://github.com/ByteHackr/unzip_poc","label":"secalert@redhat.com"},{"url":"https://lists.debian.org/debian-lts-announce/2022/09/msg00028.html","label":"secalert@redhat.com"},{"url":"https://security.gentoo.org/glsa/202310-17","label":"secalert@redhat.com"},{"url":"https://support.apple.com/kb/HT213255","label":"secalert@redhat.com"},{"url":"https://support.apple.com/kb/HT213256","label":"secalert@redhat.com"},{"url":"https://support.apple.com/kb/HT213257","label":"secalert@redhat.com"},{"url":"https://www.debian.org/security/2022/dsa-5202","label":"secalert@redhat.com"},{"url":"http://seclists.org/fulldisclosure/2022/May/33","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://seclists.org/fulldisclosure/2022/May/35","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://seclists.org/fulldisclosure/2022/May/38","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2051395","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/ByteHackr/unzip_poc","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2022/09/msg00028.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202310-17","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.apple.com/kb/HT213255","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.apple.com/kb/HT213256","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.apple.com/kb/HT213257","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2022/dsa-5202","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.02108,"epssPercentile":0.81188,"ingestedAt":"2026-10-08T22:11:53.746Z","slug":"CVE-2022-0530","body":"## Overview\n\nA flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.\n\n## Affected\n\n- `unzip = 6.0`\n- `enterprise_linux = 8.0`\n- `fedora = 35`\n- `mac_os_x >= 10.15, < 10.15.7`\n- `mac_os_x = 10.15.7`\n- `macos >= 11.0, < 11.6.6`\n- `macos >= 12.0.0, < 12.4`\n- `debian_linux = 10.0`\n- `debian_linux = 11.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `mac_os_x 10.15.7`\n- `macos 12.4`","depth":"sunlit","depthScore":31,"depthScoreParts":{"impact":30.3,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}