4.3
CVSSv2

CVE-2018-7727

Published: 06/03/2018 Updated: 03/10/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in ZZIPlib 0.13.68. There is a memory leak triggered in the function zzip_mem_disk_new in memdisk.c, which will lead to a denial of service attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zziplib project zziplib 0.13.68

redhat enterprise linux workstation 7.0

redhat enterprise linux desktop 7.0

redhat enterprise linux server 7.0

Vendor Advisories

Synopsis Low: zziplib security update Type/Severity Security Advisory: Low Topic An update for zziplib is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, which gives a det ...
Debian Bug report logs - #913165 zziplib: CVE-2018-7726 CVE-2018-7725 Package: src:zziplib; Maintainer for src:zziplib is Scott Howard <showard@debianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 7 Nov 2018 18:54:02 UTC Severity: grave Tags: patch, security, upstream Found in version zziplib/0 ...
An improper input validation was found in function __zzip_fetch_disk_trailer of ZZIPlib, up to 01368, that could lead to a crash in __zzip_parse_root_directory function of zzip/ipc Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file(CVE-2018-7726) A memory leak was found in unzip-memc and unz ...
A memory leak was found in unzip-memc and unzzip-memc of ZZIPlib, up to v01368, that could lead to resource exhaustion Local attackers could leverage this vulnerability to cause a denial of service via a crafted zip file ...
A memory leak was found in unzip-memc and unzzip-memc of ZZIPlib before 01369, that could lead to resource exhaustion Local attackers could leverage this vulnerability to cause a denial of service via a crafted zip file ...