USN-6298-1: ZZIPlib vulnerabilities
Liu Zhu discovered that ZZIPlib incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2018-7727) YiMing Liu discovered that ZZIPlib incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2020-18442)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6298-1?
The severity of USN-6298-1 is classified as a denial of service vulnerability.
How do I fix USN-6298-1?
To fix USN-6298-1, upgrade your ZZIPlib packages to the latest version specified in the advisory.
Which systems are affected by USN-6298-1?
USN-6298-1 affects Ubuntu 20.04, 18.04, and 16.04 with specific versions of libzzip-0-13, libzzip-dev, and zziplib-bin.
What is the risk posed by USN-6298-1?
The risk posed by USN-6298-1 is the potential for denial of service if a specially crafted input file is opened.
Who discovered the vulnerability in USN-6298-1?
The vulnerability in USN-6298-1 was discovered by Liu Zhu and YiMing Liu.