Advisories ยป MGASA-2021-0359

Updated zziplib packages fix security vulnerability

Publication date: 20 Jul 2021
Modification date: 20 Jul 2021
Type: security
Affected Mageia releases : 8
CVE: CVE-2020-18442

Description

Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of
service via the return value "zzip_file_read" in the function
"unzzip_cat_file" (CVE-2020-18442).
                

References

SRPMS

8/core