CVE-2012-1162

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
12/07/2012
Last modified:
11/04/2025

Description

Heap-based buffer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a zip archive with the number of directories set to 0, related to an "incorrect loop construct."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nih:libzip:0.10:*:*:*:*:*:*:*