Logo
vulnerabilityCVE-2023-46228
Name
CVE-2023-46228
Source
NVD ( link)Debian ( link)
Description
zchunk before 1.3.2 has multiple integer overflows via malformed zchunk files to lib/comp/comp.c, lib/comp/zstd/zstd.c, lib/dl/multipart.c, or lib/header.c.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
zchunk
Patched

Vulnerability Ratings#


7.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.3.2
Not Affected
buildroot
master
1.3.2
Not Affected
yocto
master
1.5.3
Not Affected
yocto
scarthgap
1.4.0
Not Affected

Resolved with patches#


zchunk (yocto:kirkstone)

#
Title
Author
Resolve
1
Handle overflow errors in malformed zchunk files
Jonathan Dieter <jdieter@gmail.com>
CVE-2023-46228