---
id: CVE-2022-0529
title: A flaw was found in Unzip
summary: >-
  A flaw was found in Unzip. The vulnerability occurs during the conversion of a
  wide string to a local string that leads to a heap of out-of-bound write. This
  flaw allows an attacker to input a specially crafted zip file, leading to a
  cra…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'
cwe:
  - CWE-787
vendor: unzip_project
product: unzip
affected:
  - unzip = 6.0
  - enterprise_linux = 8.0
  - fedora = 35
  - debian_linux = 10.0
  - debian_linux = 11.0
published: '2022-02-09'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:43.590'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-0529'
references:
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2051395'
    label: secalert@redhat.com
  - url: 'https://github.com/ByteHackr/unzip_poc'
    label: secalert@redhat.com
  - url: 'https://lists.debian.org/debian-lts-announce/2022/09/msg00028.html'
    label: secalert@redhat.com
  - url: 'https://security.gentoo.org/glsa/202310-17'
    label: secalert@redhat.com
  - url: 'https://www.debian.org/security/2022/dsa-5202'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2051395'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/ByteHackr/unzip_poc'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2022/09/msg00028.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202310-17'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2022/dsa-5202'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.02421
epssPercentile: 0.83672
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/nanaao/unzip_poc'
    - 'https://github.com/ByteHackr/unzip_poc'
  checkedAt: '2026-10-08T22:12:30.002Z'
exploitAvailable: true
ingestedAt: '2026-10-08T22:11:53.746Z'
---

## Overview

A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

## Affected

- `unzip = 6.0`
- `enterprise_linux = 8.0`
- `fedora = 35`
- `debian_linux = 10.0`
- `debian_linux = 11.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
