CVE-2018-6484: Medium severity Zziplib Project Zziplib vulnerability
In ZZIPlib 0.13.67, there is a memory alignment error and bus error in the zzipfetchdisktrailer function of zzip/zip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/zziplibto a version that resolves this vulnerability.Fixed in 0.13.62-3.3+deb11u1Fixed in 0.13.72+dfsg.1-1.1Fixed in 0.13.72+dfsg.1-1.2Fixed in 0.13.72+dfsg.1-1.3 - Upgrade
Upgrade
zziplib/zziplibto a version that resolves this vulnerability.Fixed in 0.13.67
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6484?
CVE-2018-6484 has a high severity as it can lead to denial of service through memory alignment errors.
How do I fix CVE-2018-6484?
To fix CVE-2018-6484, you should update ZZIPlib to a version higher than 0.13.67.
What platforms are affected by CVE-2018-6484?
CVE-2018-6484 affects ZZIPlib version 0.13.67 and earlier versions on various platforms including Debian and Ubuntu.
Can CVE-2018-6484 be exploited remotely?
Yes, CVE-2018-6484 can be exploited remotely through crafted zip files.
Is CVE-2018-6484 still a concern for users of ZZIPlib?
Yes, users of ZZIPlib need to be cautious of CVE-2018-6484 until they ensure they are using a patched version.