First published: Tue Jul 03 2018(Updated: )
It was discovered that zziplib incorrectly handled certain malformed ZIP files. If a user or automated system were tricked into opening a specially crafted ZIP file, a remote attacker could cause zziplib to crash, resulting in a denial of service, or possibly execute arbitrary code.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libzzip-0-13 | <0.13.62-3.1ubuntu0.18.04.1 | 0.13.62-3.1ubuntu0.18.04.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/libzzip-0-13 | <0.13.62-3.1ubuntu0.17.10.1 | 0.13.62-3.1ubuntu0.17.10.1 |
Ubuntu OpenSSH Client | =17.10 | |
All of | ||
ubuntu/libzzip-0-13 | <0.13.62-3ubuntu0.16.04.2 | 0.13.62-3ubuntu0.16.04.2 |
Ubuntu OpenSSH Client | =16.04 | |
All of | ||
ubuntu/libzzip-0-13 | <0.13.62-2ubuntu0.2 | 0.13.62-2ubuntu0.2 |
Ubuntu OpenSSH Client | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
USN-3699-1 has a severity rating that indicates it can lead to denial of service or potentially arbitrary code execution.
To fix USN-3699-1, you should update the 'libzzip-0-13' package to the latest version available for your Ubuntu release.
USN-3699-1 affects Ubuntu versions 18.04, 17.10, 16.04, and 14.04.
USN-3699-1 addresses a vulnerability in zziplib that can cause crashes of the application when processing malformed ZIP files.
Yes, USN-3699-1 can potentially allow a remote attacker to induce a denial of service or execute arbitrary code on a vulnerable system.