IO::Uncompress::Unzip是PMQS个人开发者的一个解压库。 IO::Uncompress::Unzip 2.220之前版本存在安全漏洞,该漏洞源于fastForward中每字节读取循环导致CPU耗尽,fastForward将长度偏移量(偏移量的数字位数,1到19)与块大小$c进行比较而非$offset本身,导致$c从16 KiB每次迭代缩小到1-19字节,从攻击者提供的zip中提取命名条目时驱动每字节读取循环,规模可达非Zip64的4 GiB上限。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| PMQS | IO::Uncompress::Unzip | < 2.220 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PMQS | IO::Uncompress::Unzip | 0 ~ 2.220 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48961 | IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that cra | |
| CVE-2026-48962 | IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper | |
| CVE-2025-15649 | IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when par |
No comments yet