Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2017-14107
Description:The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0 mishandles EOCD records, which allows remote attackers to cause a denial of service (memory allocation failure in _zip_cdir_grow in zip_dirent.c) via a crafted ZIP archive.
Test IDs: 1.3.6.1.4.1.25623.1.0.873398   1.3.6.1.4.1.25623.1.1.12.2021.4811.1   1.3.6.1.4.1.25623.1.1.10.2018.0020   1.3.6.1.4.1.25623.1.0.892858   1.3.6.1.4.1.25623.1.1.13.2017.255.02   1.3.6.1.4.1.25623.1.1.4.2017.2546.1   1.3.6.1.4.1.25623.1.0.873413  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2017-14107
https://blogs.gentoo.org/ago/2017/09/01/libzip-memory-allocation-failure-in-_zip_cdir_grow-zip_dirent-c/
https://github.com/nih-at/libzip/commit/9b46957ec98d85a572e9ef98301247f39338a3b5
https://lists.debian.org/debian-lts-announce/2021/12/msg00022.html




© 1998-2025 E-Soft Inc. All rights reserved.