Back

MEDIUM

zziplib: uncontrolled memory allocation in __zzip_parse_root_directory in zzip/zip.c

Published Feb 9, 2018

Description

In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function of zzip/zip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.

Affected products

Remediation

Red Hat statement

Red Hat Product Security has rated this issue as having security impact of Low. This issue does not affect the versions of ZZIPlib as shipped in Red Hat Enterprise Linux 7, unless the package is recompiled with Address Sanitizer. The flaw is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 9, 2018
Updated Aug 5, 2024
Reserved Feb 9, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Feb 8, 2018