CVE-2018-6540 - log back

CVE-2018-6540 created at 25 Sep 2019 19:31:40
Severity
+ Medium
Remote
+ Remote
Type
+ Denial of service
Description
+ In ZZIPlib 0.13.67, there is a bus error caused by loading of a misaligned address in the zzip_disk_findfirst function of zzip/mmapped.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.
References
+ https://github.com/gdraheim/zziplib/issues/15
+ https://github.com/gdraheim/zziplib/pull/19/commits/15b8c969df962a444dfa07b3d5bd4b27dc0dbba7
Notes