Bug ID 1078701
Summary VUL-0: CVE-2018-6484: zziplib: memory alignment error and bus error in the __zzip_fetch_disk_trailer function of zzip/zip.c
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.3
Hardware Other
URL https://smash.suse.de/issue/199298/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee josef.moellers@suse.com
Reporter abergmann@suse.com
QA Contact security-team@suse.de
CC wilken_g@gmx.de
Found By Security Response Team
Blocker ---

CVE-2018-6484

In ZZIPlib 0.13.67, there is a memory alignment error and bus error in the
__zzip_fetch_disk_trailer function of zzip/zip.c. Remote attackers could
leverage this vulnerability to cause a denial of service via a crafted zip
file.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-6484
https://github.com/gdraheim/zziplib/issues/14


You are receiving this mail because: