CVE-2018-16548 is a memory leak vulnerability in ZZIPlib versions up to 0.13.69, specifically within the __zzip_parse_root_directory function in zip.c, affecting the gdraheim zziplib product. This flaw can be triggered remotely with low attack complexity, leading to a denial of service (DoS) condition. While rated as Medium severity (CVSS 6.5), there is no evidence of active exploitation, publicly available exploit code, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.13.69CPE matchmatch criteria | cpe:2.3:a:gdraheim:zziplib:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2018-16548
Dec 14, 2021An issue was discovered in ZZIPlib through 0.13.69. There is a memory leak triggered in the function __zzip_parse_root_directory in zip.c which will lead to a denial of service attack.
Sep 11, 2018zziplib: Memory leak triggered in the function __zzip_parse_root_directory in zip.c
Sep 5, 2018