First published: Wed Aug 23 2017(Updated: )
Double free vulnerability in the _zip_dirent_read function in zip_dirent.c in libzip allows attackers to have unspecified impact via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libzip | =1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12858 is classified as a high severity vulnerability due to its potential for exploitation.
To fix CVE-2017-12858, update libzip to version 1.2.1 or later where the vulnerability has been patched.
CVE-2017-12858 specifically affects libzip version 1.2.0.
CVE-2017-12858 is a double free vulnerability, which may lead to memory corruption.
The impact of CVE-2017-12858 can be unspecified and may vary based on the attacker's method of exploitation.