Executive brief
A bundled command-line tool called zipdetails, which is used to display the internal structure of ZIP files, contains a software bug that causes it to crash when processing certain files. If the tool encounters a ZIP file containing specific Unix-style metadata (8-byte user or group IDs), it attempts to call a non-existent function and terminates abruptly. This issue only affects the standalone zipdetails utility and does not impact the security or stability of the core IO::Compress programming libraries used by other applications.
Technical details
A denial-of-service (crash) exists in the zipdetails CLI tool bundled with IO::Compress. The vulnerability is caused by a typo in the decode_ux() function within bin/zipdetails; when handling an Info-ZIP Unix Extra Field (tag 0x7875) with a UID or GID size of 8 bytes, the code attempts to call 'unpackValueQ' instead of the correctly defined 'unpackValue_Q'. This results in an 'Undefined subroutine' error and a script exit status of 255. The issue is restricted to the CLI tool and does not affect the IO::Compress or IO::Uncompress Perl modules. The flaw is resolved in version 2.220 (zipdetails version 4.006).
Affected products
- Perl CPAN IO::Compress 2.207 to 2.219
Timeline
- 2026-05-16: patched: Fixed in IO::Compress version 2.220
- 2026-05-27: disclosed: CVE published to NVD