Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:20838 - Security Advisory
Issued:
2025-11-11
Updated:
2025-11-11

RHSA-2025:20838 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: zziplib security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for zziplib is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The zziplib is a lightweight library to easily extract data from zip files.

Security Fix(es):

  • zziplib: directory traversal in unzzip_cat in the bins/unzzipcat-mem.c (CVE-2018-17828)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 9 Release Notes linked from the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64
  • Red Hat CodeReady Linux Builder for x86_64 9 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le
  • Red Hat CodeReady Linux Builder for ARM 64 9 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x

Fixes

  • BZ - 1635888 - CVE-2018-17828 zziplib: directory traversal in unzzip_cat in the bins/unzzipcat-mem.c

CVEs

  • CVE-2018-17828

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/9.7_release_notes/index
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
zziplib-0.13.71-12.el9.src.rpm SHA-256: a4eb51042e7ffe83efc4c3bb04c28ac5d3a30a86bfeec1017e813efb307fd908
x86_64
zziplib-0.13.71-12.el9.i686.rpm SHA-256: 33ebcad36695ec59a8615770c997906b4f772b08bc83dc092dbada5c45b93202
zziplib-0.13.71-12.el9.x86_64.rpm SHA-256: 1ed464ef1d36beaf4fae79f73a546e2dc143d681931a9f4d81a2959e86eb2fda
zziplib-debuginfo-0.13.71-12.el9.i686.rpm SHA-256: 46bcaa22aff3afaf6c3269ee15bda208a8e10323b08714db451e1668673d97de
zziplib-debuginfo-0.13.71-12.el9.x86_64.rpm SHA-256: 480f69073e4c430f05ba2cfa45a8b07f1d859ceb191bec8d811ccaba1011a8ec
zziplib-debugsource-0.13.71-12.el9.i686.rpm SHA-256: ba65a4f6ff2456486587306a7435146badeb0c3c955139d01b3f923362fd4211
zziplib-debugsource-0.13.71-12.el9.x86_64.rpm SHA-256: eb69cd87995ed46793dd411bceea17fa464407f93ced35a448e0a714290ab793
zziplib-utils-0.13.71-12.el9.x86_64.rpm SHA-256: 666b17cba45d9d02a63d53ce0ed960e2cfae15d7aa518f9a3fbeba6ee6e9665a
zziplib-utils-debuginfo-0.13.71-12.el9.i686.rpm SHA-256: df66fe6675fee707aac9c3a57b0423446798c7532261ccf663709ee310f3118d
zziplib-utils-debuginfo-0.13.71-12.el9.x86_64.rpm SHA-256: 91cee0b182bfc783abd085e6813076f8d7cd00080ea1d5c02281b124ad959803

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
zziplib-0.13.71-12.el9.src.rpm SHA-256: a4eb51042e7ffe83efc4c3bb04c28ac5d3a30a86bfeec1017e813efb307fd908
s390x
zziplib-0.13.71-12.el9.s390x.rpm SHA-256: 76e852efead5cabec8210c76a80bbf9647de580883de00b07df9f6659e001a9b
zziplib-debuginfo-0.13.71-12.el9.s390x.rpm SHA-256: 8adb7bcc91e0b4c771bc315adc5cd9d9f574e8120b5bfa952d787ffb5dcd5af7
zziplib-debugsource-0.13.71-12.el9.s390x.rpm SHA-256: cfdab30778bf4306e972980a3bfacf1d1c08c44b62209e74e7b87cb63ddf36ac
zziplib-utils-0.13.71-12.el9.s390x.rpm SHA-256: e6ef03ad4a2a0ec4d5d16483b3f170be684e806c035e973168f14f5bf229193c
zziplib-utils-debuginfo-0.13.71-12.el9.s390x.rpm SHA-256: e3386c2577b45e3a1e3df5f73b4e532cafbcf6e3cea877dc5cf807e8e57e1b73

Red Hat Enterprise Linux for Power, little endian 9

SRPM
zziplib-0.13.71-12.el9.src.rpm SHA-256: a4eb51042e7ffe83efc4c3bb04c28ac5d3a30a86bfeec1017e813efb307fd908
ppc64le
zziplib-0.13.71-12.el9.ppc64le.rpm SHA-256: 55e4163e38de04792d33d14def2959f3dda64245df4084dbf6ba77a66b0df37c
zziplib-debuginfo-0.13.71-12.el9.ppc64le.rpm SHA-256: 11fb81d0187010d35f2e53173c8a1ddcd7268faf26216bc7b37f691547df225d
zziplib-debugsource-0.13.71-12.el9.ppc64le.rpm SHA-256: 675b2348b55d40a6a7dc52dca96f5d688c052f3ca9f40c57ff51c925f48f61fa
zziplib-utils-0.13.71-12.el9.ppc64le.rpm SHA-256: 2bc30e841c1cf6d1cec9c1472cf90c0338739064753143cdaeded4fe4903a17d
zziplib-utils-debuginfo-0.13.71-12.el9.ppc64le.rpm SHA-256: 377c1ca0e24af471d89549fc0345a47b34663120e7e6d9ff047f1334ee81194c

Red Hat Enterprise Linux for ARM 64 9

SRPM
zziplib-0.13.71-12.el9.src.rpm SHA-256: a4eb51042e7ffe83efc4c3bb04c28ac5d3a30a86bfeec1017e813efb307fd908
aarch64
zziplib-0.13.71-12.el9.aarch64.rpm SHA-256: dcf9c46ca64d3d9d98b0f5a8f0008ad34ea1ea5c889a57a1dab5b3bb6819584a
zziplib-debuginfo-0.13.71-12.el9.aarch64.rpm SHA-256: fdb4a0a0474f6da99b04ec3cb81af5de8e2272037fe928f4b7ba9c1c3741b6bb
zziplib-debugsource-0.13.71-12.el9.aarch64.rpm SHA-256: 6ea00b6dace3ab8a6c2391efed6616efbf2e54bde24bb8e7d2c77e66ac615651
zziplib-utils-0.13.71-12.el9.aarch64.rpm SHA-256: 03c892a999a99f3a35cbc1a03150c05e8db0a76f22c4f174f3e073976bb1de55
zziplib-utils-debuginfo-0.13.71-12.el9.aarch64.rpm SHA-256: e4ec977b9d5f9fde3722692bb7d61f060f174a0819adbfc9f5095609f1d44c3a

Red Hat CodeReady Linux Builder for x86_64 9

SRPM
x86_64
zziplib-debuginfo-0.13.71-12.el9.i686.rpm SHA-256: 46bcaa22aff3afaf6c3269ee15bda208a8e10323b08714db451e1668673d97de
zziplib-debuginfo-0.13.71-12.el9.x86_64.rpm SHA-256: 480f69073e4c430f05ba2cfa45a8b07f1d859ceb191bec8d811ccaba1011a8ec
zziplib-debugsource-0.13.71-12.el9.i686.rpm SHA-256: ba65a4f6ff2456486587306a7435146badeb0c3c955139d01b3f923362fd4211
zziplib-debugsource-0.13.71-12.el9.x86_64.rpm SHA-256: eb69cd87995ed46793dd411bceea17fa464407f93ced35a448e0a714290ab793
zziplib-devel-0.13.71-12.el9.i686.rpm SHA-256: e65709044dfb83d1cf33be4c5e0c6f3ebbf89f87d030bab6a8b14a02f8bfb995
zziplib-devel-0.13.71-12.el9.x86_64.rpm SHA-256: dcc2ccbca99fa40d7c92f4ccd9b609fe8123f4fc9bd2a35e22a134ed714b91db
zziplib-utils-debuginfo-0.13.71-12.el9.i686.rpm SHA-256: df66fe6675fee707aac9c3a57b0423446798c7532261ccf663709ee310f3118d
zziplib-utils-debuginfo-0.13.71-12.el9.x86_64.rpm SHA-256: 91cee0b182bfc783abd085e6813076f8d7cd00080ea1d5c02281b124ad959803

Red Hat CodeReady Linux Builder for Power, little endian 9

SRPM
ppc64le
zziplib-debuginfo-0.13.71-12.el9.ppc64le.rpm SHA-256: 11fb81d0187010d35f2e53173c8a1ddcd7268faf26216bc7b37f691547df225d
zziplib-debugsource-0.13.71-12.el9.ppc64le.rpm SHA-256: 675b2348b55d40a6a7dc52dca96f5d688c052f3ca9f40c57ff51c925f48f61fa
zziplib-devel-0.13.71-12.el9.ppc64le.rpm SHA-256: 2689dafd0493624f8b50cbc8591fef78c265d26477edccbf2200f66134401592
zziplib-utils-debuginfo-0.13.71-12.el9.ppc64le.rpm SHA-256: 377c1ca0e24af471d89549fc0345a47b34663120e7e6d9ff047f1334ee81194c

Red Hat CodeReady Linux Builder for ARM 64 9

SRPM
aarch64
zziplib-debuginfo-0.13.71-12.el9.aarch64.rpm SHA-256: fdb4a0a0474f6da99b04ec3cb81af5de8e2272037fe928f4b7ba9c1c3741b6bb
zziplib-debugsource-0.13.71-12.el9.aarch64.rpm SHA-256: 6ea00b6dace3ab8a6c2391efed6616efbf2e54bde24bb8e7d2c77e66ac615651
zziplib-devel-0.13.71-12.el9.aarch64.rpm SHA-256: bb483058567973b407bbf69a330eef4e34b64e07fbd0481014046057306c5331
zziplib-utils-debuginfo-0.13.71-12.el9.aarch64.rpm SHA-256: e4ec977b9d5f9fde3722692bb7d61f060f174a0819adbfc9f5095609f1d44c3a

Red Hat CodeReady Linux Builder for IBM z Systems 9

SRPM
s390x
zziplib-debuginfo-0.13.71-12.el9.s390x.rpm SHA-256: 8adb7bcc91e0b4c771bc315adc5cd9d9f574e8120b5bfa952d787ffb5dcd5af7
zziplib-debugsource-0.13.71-12.el9.s390x.rpm SHA-256: cfdab30778bf4306e972980a3bfacf1d1c08c44b62209e74e7b87cb63ddf36ac
zziplib-devel-0.13.71-12.el9.s390x.rpm SHA-256: cea36e534ca4e9ca89d5d3cf5e89239ee0c8a26c12e2b2be1cc62e26e41d7a99
zziplib-utils-debuginfo-0.13.71-12.el9.s390x.rpm SHA-256: e3386c2577b45e3a1e3df5f73b4e532cafbcf6e3cea877dc5cf807e8e57e1b73

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility