Описание
In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function of zzip/zip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | released | 0.13.62-3.1ubuntu0.17.10.1 |
| bionic | released | 0.13.62-3.1ubuntu0.18.04.1 |
| devel | released | 0.13.62-3.1ubuntu1 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [0.13.62-2ubuntu0.2]] |
| esm-infra/bionic | released | 0.13.62-3.1ubuntu0.18.04.1 |
| esm-infra/xenial | released | 0.13.62-3ubuntu0.16.04.2 |
| precise/esm | DNE | |
| trusty | released | 0.13.62-2ubuntu0.2 |
| trusty/esm | DNE | trusty was released [0.13.62-2ubuntu0.2] |
| upstream | needs-triage |
Показывать по
EPSS
4.3 Medium
CVSS2
6.5 Medium
CVSS3
Связанные уязвимости
In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function of zzip/zip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.
In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function of zzip/zip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.
In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a c ...
In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function of zzip/zip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.
Уязвимость функции __zzip_parse_root_directory библиотеки архивирования ZZIPlib, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
4.3 Medium
CVSS2
6.5 Medium
CVSS3