CVE-2018-6381: Buffer Overflow
In ZZIPlib 0.13.67, 0.13.66, 0.13.65, 0.13.64, 0.13.63, 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57 and 0.13.56 there is a segmentation fault caused by invalid memory access in the zzipdiskfread function (zzip/mmapped.c) because the size variable is not validated against the amount of file->stored data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/zziplibto a version that resolves this vulnerability.Fixed in 0.13.62-3.3+deb11u1Fixed in 0.13.72+dfsg.1-1.1Fixed in 0.13.78+dfsg.1-0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6381?
CVE-2018-6381 has a medium severity rating due to potential denial of service from segmentation faults.
How do I fix CVE-2018-6381?
To fix CVE-2018-6381, upgrade ZZIPlib to version 0.13.72+dfsg.1-1.3 or later.
Which versions of ZZIPlib are affected by CVE-2018-6381?
ZZIPlib versions from 0.13.56 to 0.13.67 are affected by CVE-2018-6381.
What causes the vulnerability in CVE-2018-6381?
CVE-2018-6381 is caused by invalid memory access in the zzip_disk_fread function due to a lack of size validation.
Is CVE-2018-6381 specific to any operating system?
CVE-2018-6381 affects multiple operating systems including various versions of Ubuntu and Debian.