REDHAT-BUG-1626200: Low severity libzzip vulnerability
Published Sep 6, 2018
·Updated
An issue was discovered in ZZIPlib through 0.13.69. There is a memory leak triggered in the function zzipparserootdirectory in zip.c, which could lead to a denial of service attack.
Upstream issue:
https://github.com/gdraheim/zziplib/issues/58
Affected Software
1 affected component
ZZIPlib ZZIPlib<=0.13.69
Event History
Sep 6, 2018
Data Sourced
via Red Hat·05:45 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1626200?
The severity of REDHAT-BUG-1626200 is high due to the potential for a denial of service attack.
2
How do I fix REDHAT-BUG-1626200?
To fix REDHAT-BUG-1626200, you should upgrade ZZIPlib to a version newer than 0.13.69.
3
What causes the memory leak in REDHAT-BUG-1626200?
The memory leak in REDHAT-BUG-1626200 is triggered in the function __zzip_parse_root_directory in zip.c.
4
Which versions of ZZIPlib are affected by REDHAT-BUG-1626200?
ZZIPlib versions up to and including 0.13.69 are affected by REDHAT-BUG-1626200.
5
Is there a known exploit for REDHAT-BUG-1626200?
There is currently no publicly disclosed exploit specifically for REDHAT-BUG-1626200.