A Stack Buffer Overflow vulnerability in zziplibv 0.13.77 allows attackers to cause a denial of service via the __zzip_fetch_disk_trailer() function at /zzip/zip.c.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade zziplibUpgrade zziplib-utilsUpgrade zziplib-develUpgrade zziplib-debuginfo | Dec 20, 2024 | Jun 27, 2024 |
| Amazon_linux_2023 | — | Upgrade zziplib-develUpgrade zziplib-utilsUpgrade zziplib-debugsourceUpgrade zziplib-debuginfoUpgrade zziplibUpgrade zziplib-utils-debuginfo | Feb 26, 2025 | Jun 27, 2024 |
| Debian | — | Upgrade zziplibNo solution exists | May 15, 2025 | Jun 27, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 27, 2024 |
| Suse | — | Upgrade zziplib-devel-32bitUpgrade libzzip-0-13Upgrade libzzip-0-13-32bitUpgrade zziplib-devel | Aug 19, 2024 | Jun 27, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub