CVE-2018-16548: Medium severity zziplib vulnerability
An issue was discovered in ZZIPlib through 0.13.69. There is a memory leak triggered in the function zzipparserootdirectory in zip.c, which could lead to a denial of service attack.
Upstream issue:
https://github.com/gdraheim/zziplib/issues/58
Other sources
An issue was discovered in ZZIPlib through 0.13.69. There is a memory leak triggered in the function zzipparserootdirectory in zip.c, which will lead to a denial of service attack.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-16548?
CVE-2018-16548 has a severity rating that indicates a potential denial of service due to a memory leak.
How do I fix CVE-2018-16548?
To fix CVE-2018-16548, you should upgrade ZZIPlib to a version later than 0.13.69.
What systems are affected by CVE-2018-16548?
CVE-2018-16548 affects all versions of ZZIPlib up to and including 0.13.69.
What are the consequences of CVE-2018-16548?
The consequence of CVE-2018-16548 is a memory leak that can lead to a denial of service.
Is CVE-2018-16548 a high-risk vulnerability?
Yes, CVE-2018-16548 is considered a high-risk vulnerability due to its potential to disrupt service availability.