PT-2018-3397 · None+4 · Zziplib+4

Fantasy7082

·

Publicado

2018-03-06

·

Atualizado

2024-06-15

·

CVE-2018-7725

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: ZZIPlib version 0.13.68
Description: The issue is related to an invalid memory address dereference in the zzip disk fread function, which can cause an application crash leading to denial of service. The vulnerability is also described as a buffer overflow in memory, which can be exploited by a remote attacker using a specially crafted zip file to cause a denial of service.
Recommendations: For ZZIPlib version 0.13.68, consider disabling the zzip disk fread function until a patch is available to prevent potential denial of service attacks. Restrict the use of specially crafted zip files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-00744
CESA-2018_3229
CVE-2018-7725
DLA-2258-1
MGASA-2019-0093
OPENSUSE-SU-2024:11546-1
RHSA-2018:3229
RHSA-2018_3229
SUSE-SU-2018:0919-1
SUSE-SU-2018_0919-1
USN-3699-1

Produtos afetados

Centos
Red Hat
Suse
Ubuntu
Zziplib