Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

N3Vvo

#53038of 53,630
3.3Total CVSS
Vulnerabilities · 1
PT-2019-6224
3.3
2019-03-05
Zziplib · Zziplib · CVE-2020-18442
**Name of the Vulnerable Software and Affected Versions** zziplib version 0.13.69 **Description** The issue is related to an infinite loop in the `unzzip cat file` function, which can be exploited by remote attackers to cause a denial of service. This is achieved via the return value of `zzip file read`. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited. Technical details include the `unzzip cat file` function and the `zzip file read` return value. **Recommendations** For zziplib version 0.13.69, consider disabling the `unzzip cat file` function as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.