Description
The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0 mishandles EOCD records, which allows remote attackers to cause a denial of service (memory allocation failure in _zip_cdir_grow in zip_dirent.c) via a crafted ZIP archive.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2858-1 | libzip security update |
EUVD |
EUVD-2017-5619 | The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0 mishandles EOCD records, which allows remote attackers to cause a denial of service (memory allocation failure in _zip_cdir_grow in zip_dirent.c) via a crafted ZIP archive. |
Ubuntu USN |
USN-4811-1 | libzip vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T19:20:39.874Z
Reserved: 2017-09-01T00:00:00.000Z
Link: CVE-2017-14107
No data.
Status : Modified
Published: 2017-09-01T17:29:00.260
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-14107
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN