Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1541256 - (CVE-2018-6484) CVE-2018-6484 zziplib: Loading of misaligned memory address in zip.c:__zzip_fetch_disk_trailer can lead to a denial of service via crafted zip file
CVE-2018-6484 zziplib: Loading of misaligned memory address in zip.c:__zzip_f...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
impact=low,public=20180202,reported=2...
: Security
Depends On: 1541257 1541260 1545818
Blocks: 1541259
  Show dependency treegraph
 
Reported: 2018-02-02 01:26 EST by Sam Fowler
Modified: 2018-07-31 03:19 EDT (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
An unaligned memory access bug was found in the way ZZIPlib handled ZIP files. This flaw could potentially be used to crash the application using ZZIPlib by tricking the application into processing specially crafted ZIP files.
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Sam Fowler 2018-02-02 01:26:49 EST
In ZZIPlib 0.13.67, there is a memory alignment error and bus error in the __zzip_fetch_disk_trailer function of zzip/zip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.

External References:
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-6484

Upstream Issue:
https://github.com/gdraheim/zziplib/issues/14
Comment 1 Sam Fowler 2018-02-02 01:27:11 EST
Created zziplib tracking bugs for this issue:

Affects: fedora-all [bug 1541257]

Note You need to log in before you can comment on or make changes to this bug.