Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-1056

Опубликовано: 27 июл. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8
CVSS3: 7.8

Описание

An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2.1-2018/02 handled processing of ZIP files. An attacker could potentially use this flaw to crash the advzip utility by tricking it into processing crafted ZIP files.

РелизСтатусПримечание
artful

released

2.0-1ubuntu0.1
devel

not-affected

2.1-1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1.18-1ubuntu0.1]]
esm-infra/xenial

released

1.20-1ubuntu0.1
precise/esm

DNE

trusty

released

1.18-1ubuntu0.1
trusty/esm

DNE

trusty was released [1.18-1ubuntu0.1]
upstream

released

2.1-1
xenial

released

1.20-1ubuntu0.1

Показывать по

EPSS

Процентиль: 61%
0.00417
Низкий

6.8 Medium

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 3.3
redhat
около 8 лет назад

An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2.1-2018/02 handled processing of ZIP files. An attacker could potentially use this flaw to crash the advzip utility by tricking it into processing crafted ZIP files.

CVSS3: 7.8
nvd
больше 7 лет назад

An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2.1-2018/02 handled processing of ZIP files. An attacker could potentially use this flaw to crash the advzip utility by tricking it into processing crafted ZIP files.

CVSS3: 7.8
debian
больше 7 лет назад

An out-of-bounds heap buffer read flaw was found in the way advancecom ...

CVSS3: 7.8
github
больше 3 лет назад

An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2.1-2018/02 handled processing of ZIP files. An attacker could potentially use this flaw to crash the advzip utility by tricking it into processing crafted ZIP files.

EPSS

Процентиль: 61%
0.00417
Низкий

6.8 Medium

CVSS2

7.8 High

CVSS3