Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

N3Vvo

#53003de 53,632
3.3CVSS total
Vulnerabilidades · 1
PT-2019-6224
3.3
2019-03-05
Zziplib · Zziplib · CVE-2020-18442
**Name of the Vulnerable Software and Affected Versions** zziplib version 0.13.69 **Description** The issue is related to an infinite loop in the `unzzip cat file` function, which can be exploited by remote attackers to cause a denial of service. This is achieved via the return value of `zzip file read`. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited. Technical details include the `unzzip cat file` function and the `zzip file read` return value. **Recommendations** For zziplib version 0.13.69, consider disabling the `unzzip cat file` function as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.