[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2019-1142 --- zziplib

ID: oval:org.secpod.oval:def:1700134Date: (C)2019-04-22   (M)2023-12-20
Class: PATCHFamily: unix




An improper input validation was found in function __zzip_fetch_disk_trailer of ZZIPlib, up to 0.13.68, that could lead to a crash in __zzip_parse_root_directory function of zzip/ip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.A memory leak was found in unzip-mem.c and unzzip-mem.c of ZZIPlib, up to v0.13.68, that could lead to resource exhaustion. Local attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.An out of bounds read was found in function zzip_disk_fread of ZZIPlib, up to 0.13.68, when ZZIPlib mem_disk functionality is used. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.

Platform:
Amazon Linux 2
Product:
zziplib
Reference:
ALAS2-2019-1142
CVE-2018-7725
CVE-2018-7726
CVE-2018-7727
CVE    3
CVE-2018-7725
CVE-2018-7726
CVE-2018-7727
CPE    2
cpe:/a:zziplib_project:zziplib
cpe:/o:amazon:linux:2

© SecPod Technologies