Zipios before 0.1.7 does not properly handle certain malformed zip archives and can go into an infinite loop, causing a denial of service. This is related to zipheadio.h:readUint32() and zipfile.cpp:Zipfile::Zipfile().
{ "binaries": [ { "binary_name": "libzipios++0c2a", "binary_version": "0.1.5.9+cvs.2007.04.28-5.1ubuntu0.14.04.1~esm1" } ], "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro" }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-13453.json"
{ "binaries": [ { "binary_name": "flightcrew", "binary_version": "0.7.2+dfsg-6ubuntu0.1" }, { "binary_name": "libflightcrew0v5", "binary_version": "0.7.2+dfsg-6ubuntu0.1" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "libzipios++0v5", "binary_version": "0.1.5.9+cvs.2007.04.28-5.2ubuntu0.16.04.1" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "flightcrew", "binary_version": "0.7.2+dfsg-10ubuntu0.1" }, { "binary_name": "libflightcrew0v5", "binary_version": "0.7.2+dfsg-10ubuntu0.1" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "libzipios++0v5", "binary_version": "0.1.5.9+cvs.2007.04.28-10ubuntu0.18.04.1" } ], "availability": "No subscription required" }