Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-7725

Опубликовано: 07 фев. 2018
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

An issue was discovered in ZZIPlib 0.13.68. An invalid memory address dereference was discovered in zzip_disk_fread in mmapped.c. The vulnerability causes an application crash, which leads to denial of service.

An out of bounds read was found in function zzip_disk_fread of ZZIPlib, up to 0.13.68, when ZZIPlib mem_disk functionality is used. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8zziplibNot affected
Red Hat Enterprise Linux 7zziplibFixedRHSA-2018:322930.10.2018

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1554662zziplib: out of bound read in mmapped.c:zzip_disk_fread() causes crash

EPSS

Процентиль: 57%
0.00348
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

An issue was discovered in ZZIPlib 0.13.68. An invalid memory address dereference was discovered in zzip_disk_fread in mmapped.c. The vulnerability causes an application crash, which leads to denial of service.

CVSS3: 6.5
nvd
больше 7 лет назад

An issue was discovered in ZZIPlib 0.13.68. An invalid memory address dereference was discovered in zzip_disk_fread in mmapped.c. The vulnerability causes an application crash, which leads to denial of service.

CVSS3: 6.5
debian
больше 7 лет назад

An issue was discovered in ZZIPlib 0.13.68. An invalid memory address ...

CVSS3: 6.5
github
больше 3 лет назад

An issue was discovered in ZZIPlib 0.13.68. An invalid memory address dereference was discovered in zzip_disk_fread in mmapped.c. The vulnerability causes an application crash, which leads to denial of service.

CVSS3: 6.5
fstec
больше 7 лет назад

Уязвимость функции zzip_disk_fread библиотеки архивирования ZZIPlib, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 57%
0.00348
Низкий

5.4 Medium

CVSS3