Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Debian Wheezy LTS DLA-994-1 Critical: Zziplib Denial Of Service

debian lts
Calendar Grey June 20, 2017
Scroller Debian Lts
Memory exploitation in zziplib permits malicious ZIP files to induce system failures. Immediate patching advised.
CVE-2017-5974 Heap-based buffer overflow in the __zzip_get32 function in fetch.c in zziplib allows remote attackers to cause a denial of service (crash) via a crafted ZIP file

Summary

CVE-2017-5975
Heap-based buffer overflow in the __zzip_get64 function in fetch.c
in zziplib allows remote attackers to cause a denial of service
(crash) via a crafted ZIP file.

CVE-2017-5976
Heap-based buffer overflow in the zzip_mem_entry_extra_block
function in memdisk.c in zziplib allows remote attackers to cause
a denial of service (crash) via a crafted ZIP file.

CVE-2017-5978
The zzip_mem_entry_new function in memdisk.c in zziplib allows
remote attackers to cause a denial of service (out-of-bounds
read and crash) via a crafted ZIP file.

CVE-2017-5979
The prescan_entry function in fseeko.c in zziplib allows remote
attackers to cause a denial of service (NULL pointer dereference
and crash) via a crafted ZIP file.

CVE-2017-5980
The zzip_mem_entry_new function in memdisk.c in zziplib allows
remote attackers to cause a denial of service (NULL pointer
dereference and crash) via a crafted ZIP file.

CVE-2017-5981

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: zziplib
Version: 0.13.56-1.1+deb7u1
CVE ID: CVE-2017-5974 CVE-2017-5975 CVE-2017-5976 CVE-2017-5978

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.