Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-1000637

Опубликовано: 20 авг. 2018
Источник: debian

Описание

zutils version prior to version 1.8-pre2 contains a Buffer Overflow vulnerability in zcat that can result in Potential denial of service or arbitrary code execution. This attack appear to be exploitable via the victim openning a crafted compressed file. This vulnerability appears to have been fixed in 1.8-pre2.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zutilsfixed1.7-3package
zutilsfixed1.5-5+deb9u1stretchpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2018/08/05/1

  • https://lists.nongnu.org/archive/html/zutils-bug/2018-08/msg00000.html

  • Fixed by: upstream/0001-zcat-buffer-overrun.patch (in 1.7-3)

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 7 лет назад

zutils version prior to version 1.8-pre2 contains a Buffer Overflow vulnerability in zcat that can result in Potential denial of service or arbitrary code execution. This attack appear to be exploitable via the victim openning a crafted compressed file. This vulnerability appears to have been fixed in 1.8-pre2.

CVSS3: 7.8
nvd
больше 7 лет назад

zutils version prior to version 1.8-pre2 contains a Buffer Overflow vulnerability in zcat that can result in Potential denial of service or arbitrary code execution. This attack appear to be exploitable via the victim openning a crafted compressed file. This vulnerability appears to have been fixed in 1.8-pre2.

suse-cvrf
больше 7 лет назад

Security update for zutils

CVSS3: 7.8
github
больше 3 лет назад

zutils version prior to version 1.8-pre2 contains a Buffer Overflow vulnerability in zcat that can result in Potential denial of service or arbitrary code execution. This attack appear to be exploitable via the victim openning a crafted compressed file. This vulnerability appears to have been fixed in 1.8-pre2.