An issue was discovered in ZZIPlib 0.13.68. There is a memory leak triggered in the function zzip_mem_disk_new in memdisk.c, which will lead to a denial of service attack.
The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.
Link | Tags |
---|---|
https://github.com/gdraheim/zziplib/issues/40 | issue tracking third party advisory exploit |
https://access.redhat.com/errata/RHSA-2018:3229 | third party advisory vendor advisory |