---
id: CVE-2022-0530
title: A flaw was found in Unzip
summary: >-
  A flaw was found in Unzip. The vulnerability occurs during the conversion of a
  wide string to a local string that leads to a heap of out-of-bound write. This
  flaw allows an attacker to input a specially crafted zip file, leading to a
  cra…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'
vendor: unzip_project
product: unzip
affected:
  - unzip = 6.0
  - enterprise_linux = 8.0
  - fedora = 35
  - 'mac_os_x >= 10.15, < 10.15.7'
  - mac_os_x = 10.15.7
  - 'macos >= 11.0, < 11.6.6'
  - 'macos >= 12.0.0, < 12.4'
  - debian_linux = 10.0
  - debian_linux = 11.0
patched:
  - mac_os_x 10.15.7
  - macos 12.4
published: '2022-02-09'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:43.770'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-0530'
references:
  - url: 'http://seclists.org/fulldisclosure/2022/May/33'
    label: secalert@redhat.com
  - url: 'http://seclists.org/fulldisclosure/2022/May/35'
    label: secalert@redhat.com
  - url: 'http://seclists.org/fulldisclosure/2022/May/38'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2051395'
    label: secalert@redhat.com
  - url: 'https://github.com/ByteHackr/unzip_poc'
    label: secalert@redhat.com
  - url: 'https://lists.debian.org/debian-lts-announce/2022/09/msg00028.html'
    label: secalert@redhat.com
  - url: 'https://security.gentoo.org/glsa/202310-17'
    label: secalert@redhat.com
  - url: 'https://support.apple.com/kb/HT213255'
    label: secalert@redhat.com
  - url: 'https://support.apple.com/kb/HT213256'
    label: secalert@redhat.com
  - url: 'https://support.apple.com/kb/HT213257'
    label: secalert@redhat.com
  - url: 'https://www.debian.org/security/2022/dsa-5202'
    label: secalert@redhat.com
  - url: 'http://seclists.org/fulldisclosure/2022/May/33'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2022/May/35'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2022/May/38'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2051395'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/ByteHackr/unzip_poc'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2022/09/msg00028.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202310-17'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/kb/HT213255'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/kb/HT213256'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/kb/HT213257'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2022/dsa-5202'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.02108
epssPercentile: 0.81188
ingestedAt: '2026-10-08T22:11:53.746Z'
---

## Overview

A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

## Affected

- `unzip = 6.0`
- `enterprise_linux = 8.0`
- `fedora = 35`
- `mac_os_x >= 10.15, < 10.15.7`
- `mac_os_x = 10.15.7`
- `macos >= 11.0, < 11.6.6`
- `macos >= 12.0.0, < 12.4`
- `debian_linux = 10.0`
- `debian_linux = 11.0`

## Remediation

Upgrade past the affected range:

- `mac_os_x 10.15.7`
- `macos 12.4`
