PT-2018-3397 · None+4 · Zziplib+4

Fantasy7082

·

Published

2018-03-06

·

Updated

2024-06-15

·

CVE-2018-7725

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: ZZIPlib version 0.13.68
Description: The issue is related to an invalid memory address dereference in the zzip disk fread function, which can cause an application crash leading to denial of service. The vulnerability is also described as a buffer overflow in memory, which can be exploited by a remote attacker using a specially crafted zip file to cause a denial of service.
Recommendations: For ZZIPlib version 0.13.68, consider disabling the zzip disk fread function until a patch is available to prevent potential denial of service attacks. Restrict the use of specially crafted zip files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00744
CESA-2018_3229
CVE-2018-7725
DLA-2258-1
MGASA-2019-0093
OPENSUSE-SU-2024:11546-1
RHSA-2018:3229
RHSA-2018_3229
SUSE-SU-2018:0919-1
SUSE-SU-2018_0919-1
USN-3699-1

Affected Products

Centos
Red Hat
Suse
Ubuntu
Zziplib