CVE-2018-16548Missing Release of Resource after Effective Lifetime in Zziplib

Severity
6.5MEDIUMNVD
OSV9.8
EPSS
0.5%
top 34.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 5
Latest updateMay 13

Description

An issue was discovered in ZZIPlib through 0.13.69. There is a memory leak triggered in the function __zzip_parse_root_directory in zip.c, which will lead to a denial of service attack.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages7 packages

debiandebian/zziplib< zziplib 0.13.62-3.2 (bookworm)
Debiangdraheim/zziplib< 0.13.62-3.2+3
NVDgdraheim/zziplib0.13.69
Ubuntusamba/rsync< 3.1.0-2ubuntu0.4+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-7mr9-rr2r-x93g: An issue was discovered in ZZIPlib through 02022-05-13
OSV
CVE-2018-16548: An issue was discovered in ZZIPlib through 02018-09-05
OSV
rsync vulnerabilities2018-01-23

📋Vendor Advisories

3
Microsoft
An issue was discovered in ZZIPlib through 0.13.69. There is a memory leak triggered in the function __zzip_parse_root_directory in zip.c which will lead to a denial of service attack.2018-09-11
Red Hat
zziplib: Memory leak triggered in the function __zzip_parse_root_directory in zip.c2018-09-05
Debian
CVE-2018-16548: zziplib - An issue was discovered in ZZIPlib through 0.13.69. There is a memory leak trigg...2018

💬Community

2
Bugzilla
CVE-2018-16548 zziplib: Memory leak triggered in the function __zzip_parse_root_directory in zip.c [fedora-all]2018-09-06
Bugzilla
CVE-2018-16548 zziplib: Memory leak triggered in the function __zzip_parse_root_directory in zip.c2018-09-06