CVE-2017-5978: Medium severity Zziplib Project Zziplib vulnerability
Published Mar 1, 2017
·Updated
The zzipmementrynew function in memdisk.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted ZIP file.
Affected Software
2 affected components
Zziplib Project Zziplib=0.13.62
gdraheim zziplib=0.13.62
Event History
Mar 1, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5978?
CVE-2017-5978 has a severity rating classified as moderate due to potential denial of service from out-of-bounds read and crashes.
2
How do I fix CVE-2017-5978?
To fix CVE-2017-5978, update zziplib to version 0.13.63 or later where the vulnerability is patched.
3
What type of attack does CVE-2017-5978 facilitate?
CVE-2017-5978 allows remote attackers to conduct denial of service attacks through crafted ZIP files.
4
What function is affected by CVE-2017-5978?
The zzip_mem_entry_new function in memdisk.c is the specific function affected by CVE-2017-5978.
5
Which version of zziplib is vulnerable to CVE-2017-5978?
zziplib version 0.13.62 is the vulnerable version affected by CVE-2017-5978.