Memory leak in ZZIPlib - CVE-2018-16548

 

Memory leak in ZZIPlib - CVE-2018-16548

Published: September 7, 2018 / Updated: May 4, 2020


Vulnerability identifier: #VU14700
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-16548
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to cause DoS condition on the target system.

The vulnerability exists due to a memory leak in the __zzip_parse_root_directory function, as defined in the zip.c source code file. A local attacker can supply specially crafted input and cause the service to crash.


Affected software

ZZIPlib
zziplib (Alpine package)
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Opensuse

How to mitigate CVE-2018-16548

Install update from vendor's website.

ZZIPlib - update to 0.13.70
zziplib (Alpine package) - addressed in versions 0.13.69-r2, 0.13.70-r0

External References

Related Security Bulletins