Junglewise Threat Intelligence

CVE-2026-48961: Perl IO::Compress crash in zipdetails CLI tool

CVE-2026-48961 · Severity: info · CVSS 0 · Published 2026-05-27

Technologies: Perl CPAN IO-Compress. Vendors: Perl CPAN.

Executive brief

A bundled command-line tool called zipdetails, which is used to display the internal structure of ZIP files, contains a software bug that causes it to crash when processing certain files. If the tool encounters a ZIP file containing specific Unix-style metadata (8-byte user or group IDs), it attempts to call a non-existent function and terminates abruptly. This issue only affects the standalone zipdetails utility and does not impact the security or stability of the core IO::Compress programming libraries used by other applications.

Technical details

A denial-of-service (crash) exists in the zipdetails CLI tool bundled with IO::Compress. The vulnerability is caused by a typo in the decode_ux() function within bin/zipdetails; when handling an Info-ZIP Unix Extra Field (tag 0x7875) with a UID or GID size of 8 bytes, the code attempts to call 'unpackValueQ' instead of the correctly defined 'unpackValue_Q'. This results in an 'Undefined subroutine' error and a script exit status of 255. The issue is restricted to the CLI tool and does not affect the IO::Compress or IO::Uncompress Perl modules. The flaw is resolved in version 2.220 (zipdetails version 4.006).

Affected products

  • Perl CPAN IO::Compress 2.207 to 2.219

Timeline

  • 2026-05-16: patched: Fixed in IO::Compress version 2.220
  • 2026-05-27: disclosed: CVE published to NVD

References

Related threats