ALT-PU-2019-3157-1
Closed vulnerabilities
Published: 2018-08-05
BDU:2020-00739
Уязвимость функции __zzip_parse_root_directory библиотеки архивирования ZZIPlib, связанная с неосвобождением ресурса после истечения действительного срока его эксплуатирования, позволяющая нарушителю вызвать отказ в обслуживании
Severity: MEDIUM (6.5)
Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
References:
Published: 2018-09-06
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2018-16548
An issue was discovered in ZZIPlib through 0.13.69. There is a memory leak triggered in the function __zzip_parse_root_directory in zip.c, which will lead to a denial of service attack.
Severity: MEDIUM (6.5)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
References:
- openSUSE-SU-2019:2396
- openSUSE-SU-2019:2396
- openSUSE-SU-2019:2394
- openSUSE-SU-2019:2394
- RHSA-2019:2196
- RHSA-2019:2196
- https://github.com/gdraheim/zziplib/issues/58
- https://github.com/gdraheim/zziplib/issues/58
- [debian-lts-announce] 20200628 [SECURITY] [DLA 2258-1] zziplib security update
- [debian-lts-announce] 20200628 [SECURITY] [DLA 2258-1] zziplib security update
Published: 2018-10-01
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2018-17828
Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip file, because of the function unzzip_cat in the bins/unzzipcat-mem.c file.
Severity: MEDIUM (5.5)
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
References: