SUSE-SU-2024:0970-1
Dashboard / Vulnerabilities / SUSE-SU-2024:0970-1
SUSE-SU-2024:0970-1
Summary: Security update for zziplib
Details: This update for zziplib fixes the following issues: Security issue fixed: - CVE-2020-18442: Fixed infinite loop in zzip_file_read() as used in unzzip_cat_file() (bsc#1187526). - CVE-2020-18770: Fixed denial-of-service in function zzip_disk_entry_to_file_header in mmapped.c (bsc#1214577). Non-security issue fixed: - Implement an error message with a condition by checking the return value of a function call. (bsc#1154002)
References: https://www.suse.com/support/update/announcement/2024/suse-su-20240970-1/, https://bugzilla.suse.com/1154002, https://bugzilla.suse.com/1187526, https://bugzilla.suse.com/1214577, https://www.suse.com/security/cve/CVE-2020-18442, https://www.suse.com/security/cve/CVE-2020-18770
Affected packages
Package
Name: zziplib
Purl: pkg:rpm/suse/zziplib&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
