CVE-2017-5977: Medium severity Zziplib Project Zziplib vulnerability
Published Mar 1, 2017
·Updated
The zzipmementryextrablock function in memdisk.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted ZIP file.
Affected Software
2 affected components
Zziplib Project Zziplib=0.13.62
gdraheim zziplib=0.13.62
Event History
Mar 1, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5977?
CVE-2017-5977 is classified as a denial of service vulnerability due to invalid memory read and crash.
2
How do I fix CVE-2017-5977?
To mitigate CVE-2017-5977, upgrade zziplib to the latest version that addresses this vulnerability.
3
What is affected by CVE-2017-5977?
CVE-2017-5977 specifically affects zziplib version 0.13.62.
4
Can CVE-2017-5977 be exploited remotely?
Yes, CVE-2017-5977 can be exploited by remote attackers using a crafted ZIP file.
5
What is the impact of CVE-2017-5977?
The impact of CVE-2017-5977 is a potential denial of service condition leading to application crashes.