Directory traversal vulnerability in the do_extract_currentfile function in miniunz.c in miniunzip in minizip before 1.1-5 might allow remote attackers to write to arbitrary files via a crafted entry in a ZIP archive.

Project Subscriptions

Vendors Products
Zlib-ng Subscribe
Minizip-ng Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 24 Mar 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Zlib-ng
Zlib-ng minizip-ng
CPEs cpe:2.3:a:minizip_project:minizip:*:*:*:*:*:*:*:* cpe:2.3:a:zlib-ng:minizip-ng:*:*:*:*:*:*:*:*
Vendors & Products Minizip Project
Minizip Project minizip
Zlib-ng
Zlib-ng minizip-ng

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T13:47:41.174Z

Reserved: 2015-01-03T00:00:00.000Z

Link: CVE-2014-9485

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-01-16T19:29:00.497

Modified: 2026-03-24T17:24:33.077

Link: CVE-2014-9485

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses