CVE-2018-6869 is a denial-of-service vulnerability in ZZIPlib versions 0.13.68 and earlier, affecting various distributions including Canonical and Debian. It stems from an uncontrolled memory allocation within the __zzip_parse_root_directory function, allowing remote attackers to crash the application via a specially crafted zip file. Rated with a CVSS score of 6.5 (Medium), this vulnerability can be exploited over the network with low attack complexity, requiring user interaction (e.g., opening a malicious file) to achieve high availability impact. There is no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.13.68CPE matchmatch criteria | cpe:2.3:a:gdraheim:zziplib:0.13.68:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
17.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.