Back to Database
Status published
Medium
CVE-2018-16548
An issue was discovered in ZZIPlib through 0.13.69. There is...
Vulnerability Description
An issue was discovered in ZZIPlib through 0.13.69. There is a memory leak triggered in the function __zzip_parse_root_directory in zip.c, which will lead to a denial of service attack.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-16548
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/gdraheim/zziplib/issues/58
- https://access.redhat.com/errata/RHSA-2019:2196
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00065.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00066.html
- https://lists.debian.org/debian-lts-announce/2020/06/msg00029.html
More from gdraheim
View All →CVE-2020-18770
An issue was discovered in function zzip_disk_entry_to_file_header in mmapped.c in...
Medium
5.5
CVE-2020-18442
Infinite Loop in zziplib v0.13.69 allows remote attackers to cause...
Low
3.3
CVE-2018-7727
An issue was discovered in ZZIPlib 0.13.68. There is a...
Medium
6.5
CVE-2018-7726
An issue was discovered in ZZIPlib 0.13.68. There is a...
Medium
6.5
CVE-2018-7725
An issue was discovered in ZZIPlib 0.13.68. An invalid memory...
Medium
6.5
Affected Vendor
gdraheim
View all reports →Affected Software
zziplib
Vulnerable Versions:
0
Timeline
Official Publish:
September 5th, 2018
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.