CVE-2020-18442Infinite Loop in Zziplib

CWE-835Infinite Loop7 documents6 sources
Severity
3.3LOWNVD
OSV6.5
EPSS
0.1%
top 82.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 18
Latest updateAug 17

Description

Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the return value "zzip_file_read" in the function "unzzip_cat_file".

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:LExploitability: 1.8 | Impact: 1.4

Affected Packages4 packages

debiandebian/zziplib< zziplib 0.13.72+dfsg.1-1 (bookworm)
Debiangdraheim/zziplib< 0.13.62-3.3+deb11u1+3
Ubuntugdraheim/zziplib< 0.13.62-3.2ubuntu1.1+2
NVDgdraheim/zziplib0.13.69

Also affects: Debian Linux 9.0, Fedora 34, 35

Patches

🔴Vulnerability Details

3
OSV
zziplib vulnerabilities2023-08-17
GHSA
GHSA-g2w2-2g9v-p7fp: Infinite Loop in zziplib v02022-05-24
OSV
CVE-2020-18442: Infinite Loop in zziplib v02021-06-18

📋Vendor Advisories

3
Ubuntu
ZZIPlib vulnerabilities2023-08-17
Debian
CVE-2020-18442: zziplib - Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of s...2020
Red Hat
zziplib: infinite loop via the return value of zzip_file_read() as used in unzzip_cat_file()2019-03-05