Summary: | dev-libs/zziplib: Multiple vulnerabilities (CVE-2018-{6381,6484,6540,6541,6542,6869,7725,7726,7727}) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Christopher Díaz Riveros (RETIRED) <chrisadr> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | voyageur |
Priority: | Normal | Flags: | stable-bot:
sanity-check+
|
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | B3 [noglsa cve] | ||
Package list: |
dev-libs/zziplib-0.13.69
|
Runtime testing required: | --- |
Bug Depends on: | |||
Bug Blocks: | 614040 |
Description
Christopher Díaz Riveros (RETIRED)
2018-02-06 16:53:50 UTC
CVE-2018-7727 (https://nvd.nist.gov/vuln/detail/CVE-2018-7727): An issue was discovered in ZZIPlib 0.13.68. There is a memory leak triggered in the function zzip_mem_disk_new in memdisk.c, which will lead to a denial of service attack. CVE-2018-7726 (https://nvd.nist.gov/vuln/detail/CVE-2018-7726): An issue was discovered in ZZIPlib 0.13.68. There is a bus error caused by the __zzip_parse_root_directory function of zip.c. Attackers could leverage this vulnerability to cause a denial of service via a crafted zip file. CVE-2018-7725 (https://nvd.nist.gov/vuln/detail/CVE-2018-7725): An issue was discovered in ZZIPlib 0.13.68. An invalid memory address dereference was discovered in zzip_disk_fread in mmapped.c. The vulnerability causes an application crash, which leads to denial of service. CVE-2018-6869 (https://nvd.nist.gov/vuln/detail/CVE-2018-6869): In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function of zzip/zip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file. arm64 stable The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=54fcfe392afe0585141fdb078cbd631c1f79920f commit 54fcfe392afe0585141fdb078cbd631c1f79920f Author: Tobias Klausmann <klausman@gentoo.org> AuthorDate: 2019-01-30 13:19:55 +0000 Commit: Tobias Klausmann <klausman@gentoo.org> CommitDate: 2019-01-30 13:19:55 +0000 dev-libs/zziplib-0.13.69-r0: alpha stable Bug: http://bugs.gentoo.org/646780 Signed-off-by: Tobias Klausmann <klausman@gentoo.org> dev-libs/zziplib/zziplib-0.13.69.ebuild | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) sparc stable arm stable x86 stable ppc64 stable ppc stable ia64 stable hppa stable amd64 stable s390 stable GLSA vote: no. |