CVE-2017-5976

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
01/03/2017
Last modified:
10/07/2025

Description

Heap-based buffer overflow in the zzip_mem_entry_extra_block function in memdisk.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted ZIP file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gdraheim:zziplib:0.13.56:*:*:*:*:*:*:*
cpe:2.3:a:gdraheim:zziplib:0.13.57:*:*:*:*:*:*:*
cpe:2.3:a:gdraheim:zziplib:0.13.58:*:*:*:*:*:*:*
cpe:2.3:a:gdraheim:zziplib:0.13.59:*:*:*:*:*:*:*
cpe:2.3:a:gdraheim:zziplib:0.13.60:*:*:*:*:*:*:*
cpe:2.3:a:gdraheim:zziplib:0.13.61:*:*:*:*:*:*:*
cpe:2.3:a:gdraheim:zziplib:0.13.62:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*