[go: up one dir, main page]

Bug 1191696 (CVE-2018-13410) - VUL-0: CVE-2018-13410: zip: ** DISPUTED ** when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact bec
Summary: VUL-0: CVE-2018-13410: zip: ** DISPUTED ** when the -T and -TT command-line ...
Status: RESOLVED INVALID
Alias: CVE-2018-13410
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Major
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/214815/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2021-10-15 11:20 UTC by Marcus Meissner
Modified: 2021-10-15 11:21 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2021-10-15 11:20:46 UTC
CVE-2018-13410

** DISPUTED ** Info-ZIP Zip 3.0, when the -T and -TT command-line options are
used, allows attackers to cause a denial of service (invalid free and
application crash) or possibly have unspecified other impact because of an
off-by-one error. NOTE: it is unclear whether there are realistic scenarios in
which an untrusted party controls the -TT value, given that the entire purpose
of -TT is execution of arbitrary commands.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-13410
http://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-13410.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-13410
Comment 1 Marcus Meissner 2021-10-15 11:21:31 UTC
SUSE agrees with the upstream judgement and currently does not plan to fix this issue.