ALT-PU-2022-3478-1
Package zziplib updated to version 0.13.72-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
BDU:2020-00739
Уязвимость функции __zzip_parse_root_directory библиотеки архивирования ZZIPlib, связанная с неосвобождением ресурса после истечения действительного срока его эксплуатирования, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2023-11-21
BDU:2022-05680
Уязвимость функции unzzip_cat_file библиотеки архивирования ZZIPlib, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2025-07-10
CVE-2018-16548
An issue was discovered in ZZIPlib through 0.13.69. There is a memory leak triggered in the function __zzip_parse_root_directory in zip.c, which will lead to a denial of service attack.
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00065.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00066.html
- https://access.redhat.com/errata/RHSA-2019:2196
- https://github.com/gdraheim/zziplib/issues/58
- https://lists.debian.org/debian-lts-announce/2020/06/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00065.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00066.html
- https://access.redhat.com/errata/RHSA-2019:2196
- https://github.com/gdraheim/zziplib/issues/58
- https://lists.debian.org/debian-lts-announce/2020/06/msg00029.html
Modified: 2025-07-10
CVE-2018-17828
Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip file, because of the function unzzip_cat in the bins/unzzipcat-mem.c file.
Modified: 2025-07-10
CVE-2020-18442
Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the return value "zzip_file_read" in the function "unzzip_cat_file".
- https://github.com/gdraheim/zziplib/issues/68
- https://lists.debian.org/debian-lts-announce/2021/12/msg00021.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TCFYD46OY4VAGJ4UX7IFOH5SHD4UW4ZA/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VVANTEBDQGOIPC5KCEVAGA5KT4KKTGWB/
- https://github.com/gdraheim/zziplib/issues/68
- https://lists.debian.org/debian-lts-announce/2021/12/msg00021.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TCFYD46OY4VAGJ4UX7IFOH5SHD4UW4ZA/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VVANTEBDQGOIPC5KCEVAGA5KT4KKTGWB/