Un problema è stato scoperto nel ZZIPlib attraverso 0.13.69. C’è una perdita di memoria attivato nella funzione __zzip_parse_root_directory in zip.c, che porterà a un attacco denial of service. |
https://github.com/gdraheim/zziplib/issues/58 https://lists.debian.org/debian-lts-announce/2020/06/msg00029.html https://access.redhat.com/errata/RHSA-2019:2196 http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00066.html http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00065.html https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16548 |
Vulnerabilità: CVE-2018-16548
