CVE-2019-13453: Medium severity Zipios Project Zipios vulnerability
Published Jul 17, 2019
·Updated
Last updated 25 August 2025
Other sources
Zipios before 0.1.7 does not properly handle certain malformed zip archives and can go into an infinite loop, causing a denial of service. This is related to zipheadio.h:readUint32() and zipfile.cpp:Zipfile::Zipfile().
— Launchpad
Affected Software
2 affected componentsFixes available
Zipios Project Zipios<0.1.7
debian/zipios++
0.1.5.9+cvs.2007.04.28-110.1.7-20.1.7-3
Remediation
Event History
Jul 17, 2019
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
Description
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:17 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·10:51 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·10:52 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-13453?
CVE-2019-13453 has a medium severity rating as it can lead to denial of service due to an infinite loop.
2
How do I fix CVE-2019-13453?
To fix CVE-2019-13453, upgrade to Zipios version 0.1.7 or later.
3
What type of attack does CVE-2019-13453 allow?
CVE-2019-13453 allows attackers to exploit malformed zip archives to cause an infinite loop.
4
Which software versions are affected by CVE-2019-13453?
CVE-2019-13453 affects Zipios versions prior to 0.1.7.
5
What is the exploit vector for CVE-2019-13453?
The exploit vector for CVE-2019-13453 is the processing of specially crafted zip archives.