Related Vulnerabilities: CVE-2018-6542  

In ZZIPlib 0.13.67, there is a bus error (when handling a disk64_trailer seek value) caused by loading of a misaligned address in the zzip_disk_findfirst function of zzip/mmapped.c.

Severity Low

Remote No

Type Denial of service

Description

In ZZIPlib 0.13.67, there is a bus error (when handling a disk64_trailer seek value) caused by loading of a misaligned address in the zzip_disk_findfirst function of zzip/mmapped.c.

AVG-667 zziplib 0.13.67-1 0.13.68-1 Medium Fixed

https://github.com/gdraheim/zziplib/issues/17
https://github.com/gdraheim/zziplib/pull/26/commits/938011cd60f5a8a2a16a49e5f317aca640cf4110