CVE-2018-1000637: Debian Linux

High severity, CVSS 7.8. EPSS: 1.7% chance of exploitation in the next 30 days.

zutils version prior to version 1.8-pre2 contains a Buffer Overflow vulnerability in zcat that can result in Potential denial of service or arbitrary code execution. This attack appear to be exploitable via the victim openning a crafted compressed file. This vulnerability appears to have been fixed in 1.8-pre2.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Nongnu Zutils: up to and including 1.8; version 1.8 only

Published 2018-08-20. Last modified 2026-06-17.