Candidate: CVE-2018-16548 PublicDate: 2018-09-05 21:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16548 Description: An issue was discovered in ZZIPlib through 0.13.69. There is a memory leak triggered in the function __zzip_parse_root_directory in zip.c, which will lead to a denial of service attack. Ubuntu-Description: Notes: Bugs: https://github.com/gdraheim/zziplib/issues/58 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=910335 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_zziplib: upstream: https://github.com/gdraheim/zziplib/commit/0e1dadb05c1473b9df2d7b8f298dab801778ef99 upstream: https://github.com/gdraheim/zziplib/commit/d2e5d5c53212e54a97ad64b793a4389193fec687 upstream: https://github.com/gdraheim/zziplib/commit/9411bde3e4a70a81ff3ffd256b71927b2d90dcbb upstream_zziplib: needs-triage precise/esm_zziplib: DNE trusty_zziplib: ignored (reached end-of-life) trusty/esm_zziplib: DNE (trusty was needed) xenial_zziplib: ignored (end of standard support, was needed) esm-infra/xenial_zziplib: needed bionic_zziplib: needed cosmic_zziplib: ignored (reached end-of-life) disco_zziplib: not-affected (0.13.62-3.2) eoan_zziplib: not-affected (0.13.62-3.2) focal_zziplib: not-affected (0.13.62-3.2) groovy_zziplib: not-affected (0.13.62-3.2) hirsute_zziplib: not-affected (0.13.62-3.2) impish_zziplib: not-affected (0.13.62-3.2) jammy_zziplib: not-affected (0.13.62-3.2) devel_zziplib: not-affected (0.13.62-3.2)