Vulnerability Description
zchunk before 1.3.2 has multiple integer overflows via malformed zchunk files to lib/comp/comp.c, lib/comp/zstd/zstd.c, lib/dl/multipart.c, or lib/header.c.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zchunk | Zchunk | < 1.3.2 |
Related Weaknesses (CWE)
References
- https://bugzilla.suse.com/show_bug.cgi?id=1216268Issue TrackingPatchThird Party Advisory
- https://github.com/zchunk/zchunk/commit/08aec2b4dfd7f709b6e3d511411ffcc83ed4efbePatch
- https://github.com/zchunk/zchunk/compare/1.3.1...1.3.2Patch
- https://bugzilla.suse.com/show_bug.cgi?id=1216268Issue TrackingPatchThird Party Advisory
- https://github.com/zchunk/zchunk/commit/08aec2b4dfd7f709b6e3d511411ffcc83ed4efbePatch
- https://github.com/zchunk/zchunk/compare/1.3.1...1.3.2Patch
FAQ
What is CVE-2023-46228?
CVE-2023-46228 is a vulnerability with a CVSS score of 7.8 (HIGH). zchunk before 1.3.2 has multiple integer overflows via malformed zchunk files to lib/comp/comp.c, lib/comp/zstd/zstd.c, lib/dl/multipart.c, or lib/header.c.
How severe is CVE-2023-46228?
CVE-2023-46228 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-46228?
Check the references section above for vendor advisories and patch information. Affected products include: Zchunk Zchunk.