Lucene search

K
redhatcveRedhat.comRH:CVE-2024-39133
HistoryJun 28, 2024 - 5:09 a.m.

CVE-2024-39133

2024-06-2805:09:01
redhat.com
access.redhat.com
1
zziplib v0.13.77
heap buffer overflow
denial of service

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

A heap buffer overflow vulnerability was found in zziplib. This flaw allows attackers to cause a denial of service via the __zzip_parse_root_directory() function at /zzip/zip.c.

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%