CVE-2018-12913 describes an infinite loop vulnerability in the tinfl_decompress function within miniz_tinfl.c of Miniz 2.0.7, caused by sym2 and counter variables remaining at zero. This flaw carries a CVSSv3 score of 7.5 (High), indicating a critical availability impact (A:H) that can be triggered remotely without authentication (AV:N/AC:L/PR:N/UI:N). Despite its severity, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.7CPE matchmatch criteria | cpe:2.3:a:miniz_project:miniz:2.0.7:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.