CVE-2014-9485: Zlib-NG Minizip-NG

Medium severity, CVSS 5.5. EPSS: 4.1% chance of exploitation in the next 30 days.

Directory traversal vulnerability in the do_extract_currentfile function in miniunz.c in miniunzip in minizip before 1.1-5 might allow remote attackers to write to arbitrary files via a crafted entry in a ZIP archive.

Affected products

  • Zlib-NG Minizip-NG: up to and including 1.1-4

Published 2018-01-16. Last modified 2026-06-17.