First published: Fri Sep 01 2017(Updated: )
The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0 mishandles EOCD records, which allows remote attackers to cause a denial of service (memory allocation failure in _zip_cdir_grow in zip_dirent.c) via a crafted ZIP archive.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libzip | <1.3.0 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14107 has a severity rating that indicates it can lead to a denial of service due to memory allocation failures.
To fix CVE-2017-14107, upgrade libzip to version 1.3.0 or later.
CVE-2017-14107 affects libzip prior to version 1.3.0 and Debian Linux 9.0.
Yes, CVE-2017-14107 can be exploited remotely through a crafted ZIP archive.
CVE-2017-14107 can lead to memory allocation failures resulting in denial of service.