6.8
CVSSv2

CVE-2012-1163

Published: 12/07/2012 Updated: 16/07/2012
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote malicious users to execute arbitrary code via the size and offset values for the central directory in a zip archive, which triggers "improper restrictions of operations within the bounds of a memory buffer" and an information leak.

Vulnerable Product Search on Vulmon Subscribe to Product

nih libzip 0.10

Vendor Advisories

Debian Bug report logs - #664990 libzip1: CVE-2012-1162 CVE-2012-1163 Incorrect loop construct and numeric overflow Package: libzip1; Maintainer for libzip1 is (unknown); Reported by: Henri Salo <henri@nervfi> Date: Thu, 22 Mar 2012 06:00:01 UTC Severity: grave Merged with 665957 Found in versions libzip/093-1, 010-1 ...