CVE-2018-13410
Publication date 6 July 2018
Last updated 6 August 2026
Ubuntu priority
Cvss 3 Severity Score
Description
Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact because of an off-by-one error. NOTE: it is unclear whether there are realistic scenarios in which an untrusted party controls the -TT value, given that the entire purpose of -TT is execution of arbitrary commands
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| zip | 22.04 LTS jammy | Ignored see notes |
| 20.04 LTS focal | Ignored end of standard support, was ignored [see notes] | |
| 18.04 LTS bionic | Ignored end of standard support | |
| 16.04 LTS xenial | Ignored end of standard support, was needs-triage | |
| 14.04 LTS trusty | Ignored end of standard support |
Notes
rodrigo-zaiden
suse does not have plans to fix it and debian marked as negligible. There is no obvious security impact since there is no scenarios where an untrusted party controls the -TT input value.
mdeslaur
Ubuntu is ignoring this issue as the attacker scenario is unlikely and this is unlikely to ever get an fix from upstream developers.
Severity score breakdown
CVSS version: CVSS v3.0
Base score
9.8 · Critical
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H