| Name | CVE-2018-16548 |
| Description | An issue was discovered in ZZIPlib through 0.13.69. There is a memory leak triggered in the function __zzip_parse_root_directory in zip.c, which will lead to a denial of service attack. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DLA-2258-1 |
| Debian Bugs | 910335 |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| zziplib (PTS) | bullseye | 0.13.62-3.3+deb11u1 | fixed |
| bookworm | 0.13.72+dfsg.1-1.1 | fixed | |
| trixie | 0.13.78+dfsg.1-0.1 | fixed | |
| forky, sid | 0.13.78+dfsg.1-0.2 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| zziplib | source | jessie | 0.13.62-3+deb8u2 | DLA-2258-1 | ||
| zziplib | source | stretch | 0.13.62-3.2~deb9u1 | |||
| zziplib | source | (unstable) | 0.13.62-3.2 | low | 910335 |
https://github.com/gdraheim/zziplib/issues/58
https://github.com/gdraheim/zziplib/commit/9411bde3e4a70a81ff3ffd256b71927b2d90dcbb
https://github.com/gdraheim/zziplib/commit/d2e5d5c53212e54a97ad64b793a4389193fec687
https://github.com/gdraheim/zziplib/commit/0e1dadb05c1473b9df2d7b8f298dab801778ef99