Hash: SHA512

Package        : zziplib
Version        : 0.13.56-1.1+deb7u1
CVE ID         : CVE-2017-5974 CVE-2017-5975 CVE-2017-5976 CVE-2017-5978
                  CVE-2017-5979 CVE-2017-5980 CVE-2017-5981

CVE-2017-5974
      Heap-based buffer overflow in the __zzip_get32 function in fetch.c
      in zziplib allows remote attackers to cause a denial of service
      (crash) via a crafted ZIP file.

CVE-2017-5975
      Heap-based buffer overflow in the __zzip_get64 function in fetch.c
      in zziplib allows remote attackers to cause a denial of service
      (crash) via a crafted ZIP file.

CVE-2017-5976
      Heap-based buffer overflow in the zzip_mem_entry_extra_block
      function in memdisk.c in zziplib allows remote attackers to cause
      a denial of service (crash) via a crafted ZIP file.

CVE-2017-5978
      The zzip_mem_entry_new function in memdisk.c in zziplib allows
      remote attackers to cause a denial of service (out-of-bounds
      read and crash) via a crafted ZIP file.

CVE-2017-5979
      The prescan_entry function in fseeko.c in zziplib allows remote
      attackers to cause a denial of service (NULL pointer dereference
      and crash) via a crafted ZIP file.

CVE-2017-5980
      The zzip_mem_entry_new function in memdisk.c in zziplib allows
      remote attackers to cause a denial of service (NULL pointer
      dereference and crash) via a crafted ZIP file.

CVE-2017-5981
      seeko.c in zziplib allows remote attackers to cause a denial of
      service (assertion failure and crash) via a crafted ZIP file.



For Debian 7 "Wheezy", these problems have been fixed in version
0.13.56-1.1+deb7u1.

We recommend that you upgrade your zziplib packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-994-1: zziplib security update

June 20, 2017
CVE-2017-5974 Heap-based buffer overflow in the __zzip_get32 function in fetch.c in zziplib allows remote attackers to cause a denial of service (crash) via a crafted ZIP file

Summary

CVE-2017-5975
Heap-based buffer overflow in the __zzip_get64 function in fetch.c
in zziplib allows remote attackers to cause a denial of service
(crash) via a crafted ZIP file.

CVE-2017-5976
Heap-based buffer overflow in the zzip_mem_entry_extra_block
function in memdisk.c in zziplib allows remote attackers to cause
a denial of service (crash) via a crafted ZIP file.

CVE-2017-5978
The zzip_mem_entry_new function in memdisk.c in zziplib allows
remote attackers to cause a denial of service (out-of-bounds
read and crash) via a crafted ZIP file.

CVE-2017-5979
The prescan_entry function in fseeko.c in zziplib allows remote
attackers to cause a denial of service (NULL pointer dereference
and crash) via a crafted ZIP file.

CVE-2017-5980
The zzip_mem_entry_new function in memdisk.c in zziplib allows
remote attackers to cause a denial of service (NULL pointer
dereference and crash) via a crafted ZIP file.

CVE-2017-5981
...

Read the Full Advisory


Severity
Package : zziplib
Version : 0.13.56-1.1+deb7u1
CVE ID : CVE-2017-5974 CVE-2017-5975 CVE-2017-5976 CVE-2017-5978

Related News