CVE-2017-5979: Null Pointer Dereference
Published Mar 1, 2017
·Updated
The prescanentry function in fseeko.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted ZIP file.
Affected Software
2 affected components
Zziplib Project Zziplib=0.13.62
gdraheim zziplib=0.13.62
Event History
Mar 1, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5979?
CVE-2017-5979 has been classified as a denial of service vulnerability due to a NULL pointer dereference.
2
What software is affected by CVE-2017-5979?
CVE-2017-5979 specifically affects zziplib version 0.13.62.
3
How do I fix CVE-2017-5979?
To fix CVE-2017-5979, upgrade zziplib to a version that is not vulnerable to this issue.
4
Can CVE-2017-5979 be exploited remotely?
Yes, CVE-2017-5979 can be exploited by remote attackers using crafted ZIP files.
5
What type of attack does CVE-2017-5979 facilitate?
CVE-2017-5979 facilitates a denial of service attack due to application crashes caused by certain ZIP files.