CVE Vulnerabilities

CVE-2020-18442

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jun 18, 2021 | Modified: Jul 10, 2025
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
3.3 LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the return value zzip_file_read in the function unzzip_cat_file.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

NameVendorStart VersionEnd Version
ZziplibGdraheim0.13.69 (including)0.13.69 (including)
Red Hat Enterprise Linux 8RedHatzziplib-0:0.13.68-9.el8*
ZziplibUbuntubionic*
ZziplibUbuntuesm-apps/focal*
ZziplibUbuntuesm-infra/bionic*
ZziplibUbuntuesm-infra/xenial*
ZziplibUbuntufocal*
ZziplibUbuntugroovy*
ZziplibUbuntuhirsute*
ZziplibUbuntuimpish*
ZziplibUbuntukinetic*
ZziplibUbuntutrusty*
ZziplibUbuntuupstream*
ZziplibUbuntuxenial*

References