Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive.
The product does not properly verify that the source of data or communication is valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zip4j | Zip4j_project | * | 2.11.2 (including) |
Migration Toolkit for Runtimes 1 on RHEL 8 | RedHat | org.jboss.windup-windup-parent | * |
MTA-6.2-RHEL-9 | RedHat | mta/mta-operator-bundle:6.2.0-29 | * |
Zip4j | Ubuntu | kinetic | * |
Zip4j | Ubuntu | lunar | * |
Zip4j | Ubuntu | mantic | * |
Zip4j | Ubuntu | trusty | * |
Zip4j | Ubuntu | xenial | * |