CVE-2018-6542: Medium severity Zziplib Project Zziplib vulnerability
Published Feb 2, 2018
·Updated
In ZZIPlib 0.13.67, there is a bus error (when handling a disk64trailer seek value) caused by loading of a misaligned address in the zzipdiskfindfirst function of zzip/mmapped.c.
Affected Software
2 affected components
Zziplib Project Zziplib=0.13.67
gdraheim zziplib=0.13.67
Event History
Feb 2, 2018
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
Data Sourced
via NVD·09:29 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-6542?
CVE-2018-6542 is classified as a moderate severity vulnerability.
2
How does CVE-2018-6542 affect ZZIPlib 0.13.67?
CVE-2018-6542 affects ZZIPlib 0.13.67 by causing a bus error due to the handling of a misaligned address.
3
How do I fix CVE-2018-6542?
To fix CVE-2018-6542, you should upgrade to a version of ZZIPlib that is later than 0.13.67.
4
What function in ZZIPlib is vulnerable in CVE-2018-6542?
The vulnerable function in ZZIPlib as identified by CVE-2018-6542 is zzip_disk_findfirst.
5
Is CVE-2018-6542 present in earlier versions of ZZIPlib?
CVE-2018-6542 is specifically identified in version 0.13.67 of ZZIPlib and may not affect earlier versions.