First published: Wed Mar 01 2017(Updated: )
seeko.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (assertion failure and crash) via a crafted ZIP file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
zziplib | =0.13.62 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5981 has a moderate severity level as it can cause denial of service due to an assertion failure and crash.
To fix CVE-2017-5981, you should upgrade to a newer version of zziplib that has addressed the vulnerability.
CVE-2017-5981 is associated with remote denial of service attacks through crafted ZIP files.
CVE-2017-5981 specifically affects zziplib version 0.13.62.
Yes, CVE-2017-5981 can be exploited without user interaction by sending a malicious ZIP file to the target application.