Zziplib · Zziplib · CVE-2024-39134
**Name of the Vulnerable Software and Affected Versions**
zziplib version 0.13.77
**Description**
The issue is related to a buffer copy without input validation in the ` zzip fetch disk trailer()` function of the `/zzip/zip.c` component in the ZZIPlib archiving library. This can be exploited by a remote attacker to cause a denial of service.
**Recommendations**
For version 0.13.77, consider disabling the ` zzip fetch disk trailer()` function as a temporary workaround until a patch is available. Restrict access to the `/zzip/zip.c` component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.