SUSE update for zziplib



Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2020-18442
CWE-ID CWE-835
Exploitation vector Network
Public exploit N/A
Vulnerable software
SUSE Linux Enterprise Workstation Extension
Operating systems & Components / Operating system

SUSE Linux Enterprise Software Development Kit
Operating systems & Components / Operating system

zziplib-devel-debuginfo
Operating systems & Components / Operating system package or component

zziplib-devel
Operating systems & Components / Operating system package or component

zziplib-debugsource
Operating systems & Components / Operating system package or component

libzzip-0-13-debuginfo
Operating systems & Components / Operating system package or component

libzzip-0-13
Operating systems & Components / Operating system package or component

Vendor SUSE

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Infinite loop

EUVDB-ID: #VU79772

Risk: Low

CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2020-18442

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop within the unzzip_cat_file() function. A remote attacker can consume all available system resources and cause denial of service conditions.

Mitigation

Update the affected package zziplib to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Workstation Extension: 12-SP5

SUSE Linux Enterprise Software Development Kit: 12-SP5

zziplib-devel-debuginfo: before 0.13.67-10.33.1

zziplib-devel: before 0.13.67-10.33.1

zziplib-debugsource: before 0.13.67-10.33.1

libzzip-0-13-debuginfo: before 0.13.67-10.33.1

libzzip-0-13: before 0.13.67-10.33.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2021/suse-su-20212164-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###