7.5
CVSSv2

CVE-2012-1162

Published: 12/07/2012 Updated: 13/07/2012
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote malicious users to cause a denial of service (application crash) and possibly execute arbitrary code via a zip archive with the number of directories set to 0, related to an "incorrect loop construct."

Vulnerable Product Search on Vulmon Subscribe to Product

nih libzip 0.10

Vendor Advisories

Debian Bug report logs - #664990 libzip1: CVE-2012-1162 CVE-2012-1163 Incorrect loop construct and numeric overflow Package: libzip1; Maintainer for libzip1 is (unknown); Reported by: Henri Salo <henri@nervfi> Date: Thu, 22 Mar 2012 06:00:01 UTC Severity: grave Merged with 665957 Found in versions libzip/093-1, 010-1 ...