Описание
Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the return value "zzip_file_read" in the function "unzzip_cat_file".
Отчет
Red Hat Enterprise 7 is not affected by this flaw because it shipped with a version prior to the flaw being introduced.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 7 | zziplib | Not affected | ||
Red Hat Enterprise Linux 9 | zziplib | Not affected | ||
Red Hat Enterprise Linux 8 | zziplib | Fixed | RHSA-2021:4316 | 09.11.2021 |
Показывать по
10
Дополнительная информация
Статус:
Low
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1973826zziplib: infinite loop via the return value of zzip_file_read() as used in unzzip_cat_file()
EPSS
Процентиль: 18%
0.00058
Низкий
3.3 Low
CVSS3
Связанные уязвимости
CVSS3: 3.3
ubuntu
около 4 лет назад
Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the return value "zzip_file_read" in the function "unzzip_cat_file".
CVSS3: 3.3
nvd
около 4 лет назад
Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the return value "zzip_file_read" in the function "unzzip_cat_file".
CVSS3: 3.3
debian
около 4 лет назад
Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a d ...
EPSS
Процентиль: 18%
0.00058
Низкий
3.3 Low
CVSS3