![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2017-14107 |
Description: | The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0 mishandles EOCD records, which allows remote attackers to cause a denial of service (memory allocation failure in _zip_cdir_grow in zip_dirent.c) via a crafted ZIP archive. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.873398 1.3.6.1.4.1.25623.1.1.12.2021.4811.1 1.3.6.1.4.1.25623.1.1.10.2018.0020 1.3.6.1.4.1.25623.1.0.892858 1.3.6.1.4.1.25623.1.1.13.2017.255.02 1.3.6.1.4.1.25623.1.1.4.2017.2546.1 1.3.6.1.4.1.25623.1.0.873413 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2017-14107 https://blogs.gentoo.org/ago/2017/09/01/libzip-memory-allocation-failure-in-_zip_cdir_grow-zip_dirent-c/ https://github.com/nih-at/libzip/commit/9b46957ec98d85a572e9ef98301247f39338a3b5 https://lists.debian.org/debian-lts-announce/2021/12/msg00022.html |