« Volver al listado

CVE-2026-48961

Estado: AplazadaAlta (7.3)—

IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.

When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.

Leer descripción completaMostrar menos

Library callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Aplicación expuesta (zipdetails CLI) que crashea por entrada malformada en archivo ZIP, causando DoS. No hay ejecución de código, solo denegación de servicio.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-48961",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-48961",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-29T15:51:41.495552Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.3,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
      "affectedData": [
        {
          "repo": "https://github.com/pmqs/IO-Compress",
          "vendor": "PMQS",
          "product": "IO::Compress",
          "versions": [
            {
              "status": "affected",
              "version": "2.207",
              "lessThan": "2.220",
              "versionType": "custom"
            }
          ],
          "packageName": "IO-Compress",
          "programFiles": [
            "bin/zipdetails"
          ],
          "collectionURL": "https://cpan.org/modules",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "main::decode_ux"
            },
            {
              "name": "main::decodeLitteEndian"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-05-27T04:16:31.210",
  "references": [
    {
      "url": "https://github.com/pmqs/IO-Compress/commit/33c89d03d6e746ed2ead4f2f6570d47864c61bc7.patch",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://metacpan.org/release/PMQS/IO-Compress-2.220/changes",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2026/05/27/3",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
      "description": [
        {
          "lang": "en",
          "value": "CWE-755"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.\n\nWhen decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.\n\nLibrary callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool."
    },
    {
      "lang": "es",
      "value": "Las versiones de IO::Compress desde la 2.207 anteriores a la 2.220 para Perl distribuyen una herramienta CLI zipdetails que falla con subrutina indefinida en el campo extra Unix de Info-ZIP con UID o GID de 8 bytes.\n\nCuando decode_ux() en bin/zipdetails maneja un campo extra Unix de Info-ZIP (etiqueta 0x7875) con el tamaño de UID o el tamaño de GID establecido en 8, lo que hace que zipdetails decodifique un valor UID o GID de 8 bytes, se despacha a través de decodeLitteEndian(), que llama a una función auxiliar mal nombrada unpackValueQ. La función real definida en el mismo archivo es unpackValue_Q (con guion bajo); la llamada genera 'Undefined subroutine &main::unpackValueQ' y el script sale con estado 255.\n\nLos llamadores de biblioteca de IO::Compress y IO::Uncompress no se ven afectados; el defecto está en la herramienta CLI incluida."
    }
  ],
  "lastModified": "2026-07-24T12:10:00.210",
  "sourceIdentifier": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
}