Heap-based buffer overflow in the __zzip_get32 function in fetch.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted ZIP file.
2017-03-01T15:59:01.117
2025-07-10T15:44:54.403
Deferred
CVSSv3.1: 5.5 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:N/A:P
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gdraheim | zziplib | 0.13.56 | Yes |
Application | gdraheim | zziplib | 0.13.57 | Yes |
Application | gdraheim | zziplib | 0.13.58 | Yes |
Application | gdraheim | zziplib | 0.13.59 | Yes |
Application | gdraheim | zziplib | 0.13.60 | Yes |
Application | gdraheim | zziplib | 0.13.61 | Yes |
Application | gdraheim | zziplib | 0.13.62 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |