CVE-2018-6541: Medium severity Zziplib Project Zziplib vulnerability
A flaw was found in ZZIPlib 0.13.67, there is a bus error caused by loading of a misaligned address (when handling disk64trailer local entries) in zzipfetchdisktrailer (zzip/zip.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.
References: https://github.com/gdraheim/zziplib/issues/16
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/zziplibto a version that resolves this vulnerability.Fixed in 0.13.68 - Upgrade
Upgrade
debian/zziplibto a version that resolves this vulnerability.Fixed in 0.13.62-3.3+deb11u1Fixed in 0.13.72+dfsg.1-1.1Fixed in 0.13.72+dfsg.1-1.2Fixed in 0.13.72+dfsg.1-1.3 - Upgrade
Upgrade
zziplibto a version that resolves this vulnerability.Fixed in 0.13.67 - Compensating control
Mitigate denial-of-service risk by preventing or tightly restricting the handling of untrusted/crafted ZIP files that could trigger the bus error in __zzip_fetch_disk_trailer (zzip/zip.c).
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6541?
CVE-2018-6541 is categorized as a denial of service vulnerability.
How do I fix CVE-2018-6541?
To fix CVE-2018-6541, upgrade ZZIPlib to version 0.13.68 or later.
What software is affected by CVE-2018-6541?
CVE-2018-6541 affects ZZIPlib version 0.13.67.
Can CVE-2018-6541 be exploited remotely?
Yes, CVE-2018-6541 can be exploited remotely by using crafted zip files.
What types of systems are impacted by CVE-2018-6541?
CVE-2018-6541 impacts systems using ZZIPlib, including certain versions of Ubuntu and Debian.