4.3
CVSSv2

CVE-2017-14107

Published: 01/09/2017 Updated: 06/04/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The _zip_read_eocd64 function in zip_open.c in libzip prior to 1.3.0 mishandles EOCD records, which allows remote malicious users to cause a denial of service (memory allocation failure in _zip_cdir_grow in zip_dirent.c) via a crafted ZIP archive.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libzip libzip

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #874010 libzip: CVE-2017-14107: memory allocation failure in _zip_cdir_grow (zip_direntc) Package: src:libzip; Maintainer for src:libzip is Stefan Schörghofer <amd1212@4mdgr>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 1 Sep 2017 21:15:01 UTC Severity: important Tags ...
The _zip_read_eocd64 function in zip_openc in libzip before 130 mishandles EOCD records, which allows remote attackers to cause a denial of service (memory allocation failure in _zip_cdir_grow in zip_direntc) via a crafted ZIP archive ...