{"id":"CVE-2018-13410","title":"Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact because of an off-by-one error","summary":"Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact because of an off-by-one error. NOTE: it is…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-416"],"vendor":"info-zip_project","product":"zip","affected":["zip = 3.0"],"published":"2018-07-06","updated":"2026-09-18","sourceUpdated":"2026-09-18T11:17:06.010","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2018-13410","references":[{"url":"http://seclists.org/fulldisclosure/2018/Jul/24","label":"cve@mitre.org"},{"url":"http://seclists.org/fulldisclosure/2018/Jul/24","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2026/09/msg00020.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available","cve.org"],"epss":0.03298,"epssPercentile":0.87977,"exploits":{"github":1,"githubRepos":["https://github.com/shinecome/zip"],"checkedAt":"2026-09-21T15:23:37.993Z"},"exploitAvailable":true,"ingestedAt":"2026-09-18T10:39:24.460Z","slug":"CVE-2018-13410","body":"## Overview\n\nInfo-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact because of an off-by-one error. NOTE: it is unclear whether there are realistic scenarios in which an untrusted party controls the -TT value, given that the entire purpose of -TT is execution of arbitrary commands\n\n## Affected\n\n- `zip = 3.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":67,"depthScoreParts":{"impact":53.9,"likelihood":0.7,"exploitation":12,"ransomware":0},"changes":[{"seq":206710,"id":"CVE-2018-13410","ts":1789731638283,"field":"cvss","old":null,"new":"9.8"},{"seq":206709,"id":"CVE-2018-13410","ts":1789731638283,"field":"severity","old":"none","new":"critical"}]}