Vulnerability CVE-2018-16548: Information
Description
An issue was discovered in ZZIPlib through 0.13.69. There is a memory leak triggered in the function __zzip_parse_root_directory in zip.c, which will lead to a denial of service attack.
Severity: MEDIUM (6.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
zziplib | sisyphus | 0.13.69-alt2 | 0.13.72-alt1 | ALT-PU-2019-2518-1 | 236408 | Fixed |
zziplib | sisyphus_riscv64 | 0.13.72-alt1 | 0.13.72-alt1 | ALT-PU-2022-3478-1 | - | Fixed |
zziplib | p10 | 0.13.69-alt2 | 0.13.72-alt1 | ALT-PU-2019-2518-1 | 236408 | Fixed |
zziplib | p9 | 0.13.69-alt3 | 0.13.69-alt3 | ALT-PU-2019-3157-1 | 240930 | Fixed |
zziplib | c10f1 | 0.13.69-alt2 | 0.13.72-alt1 | ALT-PU-2019-2518-1 | 236408 | Fixed |
zziplib | c9f2 | 0.13.69-alt3 | 0.13.69-alt3 | ALT-PU-2019-3157-1 | 240930 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://github.com/gdraheim/zziplib/issues/58 |
|
RHSA-2019:2196 | |
openSUSE-SU-2019:2396 | |
openSUSE-SU-2019:2394 | |
[debian-lts-announce] 20200628 [SECURITY] [DLA 2258-1] zziplib security update |