A Stack Buffer Overflow vulnerability in zziplibv 0.13.77 allows attackers to cause a denial of service via the __zzip_fetch_disk_trailer() function at /zzip/zip.c.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade zziplibUpgrade zziplib-debuginfoUpgrade zziplib-develUpgrade zziplib-utils | Dec 20, 2024 | Jun 27, 2024 |
| Amazon_linux_2023 | — | Upgrade zziplib-debuginfoUpgrade zziplibUpgrade zziplib-debugsourceUpgrade zziplib-utils-debuginfoUpgrade zziplib-develUpgrade zziplib-utils | Feb 26, 2025 | Jun 27, 2024 |
| Debian | — | Upgrade zziplib | May 15, 2025 | Jun 27, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 27, 2024 |
| Suse | — | Upgrade zziplib-develUpgrade libzzip-0-13Upgrade zziplib-devel-32bitUpgrade libzzip-0-13-32bit | Aug 19, 2024 | Jun 27, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub