CVE-2012-1163: Integer Overflow
Integer overflow in the zipreadcdir function in zipopen.c in libzip 0.10 allows remote attackers to execute arbitrary code via the size and offset values for the central directory in a zip archive, which triggers "improper restrictions of operations within the bounds of a memory buffer" and an information leak.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1163?
CVE-2012-1163 is considered to have a critical severity rating due to the potential for remote code execution.
How do I fix CVE-2012-1163?
To fix CVE-2012-1163, update to a newer version of libzip that has addressed this vulnerability.
What software versions are affected by CVE-2012-1163?
CVE-2012-1163 specifically affects libzip version 0.10.
Can CVE-2012-1163 be exploited remotely?
Yes, CVE-2012-1163 can be exploited remotely by attackers through crafted zip archives.
What action should I take if I am using an affected version of libzip?
If you are using an affected version of libzip, you should immediately apply security updates or patches to mitigate the risk.