Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-13410

Опубликовано: 06 июл. 2018
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8

Описание

Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact because of an off-by-one error. NOTE: it is unclear whether there are realistic scenarios in which an untrusted party controls the -TT value, given that the entire purpose of -TT is execution of arbitrary commands

РелизСтатусПримечание
artful

ignored

end of life
bionic

ignored

end of standard support
cosmic

ignored

end of life
devel

ignored

disputed
disco

ignored

end of life
eoan

ignored

end of life
esm-infra-legacy/trusty

ignored

disputed
esm-infra/bionic

ignored

disputed
esm-infra/focal

ignored

disputed
esm-infra/xenial

ignored

disputed

Показывать по

EPSS

Процентиль: 90%
0.0517
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
около 7 лет назад

Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact because of an off-by-one error. NOTE: it is unclear whether there are realistic scenarios in which an untrusted party controls the -TT value, given that the entire purpose of -TT is execution of arbitrary commands

CVSS3: 9.8
msrc
около 5 лет назад

Описание отсутствует

CVSS3: 9.8
debian
около 7 лет назад

Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, a ...

CVSS3: 9.8
github
больше 3 лет назад

** DISPUTED ** Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact because of an off-by-one error. NOTE: it is unclear whether there are realistic scenarios in which an untrusted party controls the -TT value, given that the entire purpose of -TT is execution of arbitrary commands.

CVSS3: 9.8
fstec
около 7 лет назад

Уязвимость программного обеспечения для сжатия файлов zip, связанная с использованием памяти после её освобождения, позволяющая нарушителю получить доступ к конфиденциальной информации или вызвать отказ в обслуживании

EPSS

Процентиль: 90%
0.0517
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3