
CVE-2018-13410
https://notcve.org/view.php?id=CVE-2018-13410
06 Jul 2018 — Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact because of an off-by-one error. NOTE: it is unclear whether there are realistic scenarios in which an untrusted party controls the -TT value, given that the entire purpose of -TT is execution of arbitrary commands ** EN DISPUTA ** Info-ZIP Zip 3.0, cuando se emplean las opciones de la línea de comandos -T y -TT, perm... • https://github.com/shinecome/zip • CWE-416: Use After Free •

CVE-2004-1010
https://notcve.org/view.php?id=CVE-2004-1010
09 Nov 2004 — Buffer overflow in Info-Zip 2.3 and possibly earlier versions, when using recursive folder compression, allows remote attackers to execute arbitrary code via a ZIP file containing a long pathname. • http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/028379.html •