Resource exhaustion in libzip - CVE-2017-14107
Published: August 3, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The
vulnerability exists due to a boundary error when processing EOCD
records in _zip_read_eocd64() function in zip_open.c in libzip. A remote
attacker can create a specially crafted ZIP archive, trick the victim
into opening it and consume all available memory on the system.
Affected software
libzip (Alpine package)
mingw-libzip
libzip
Slackware Linux
Fedora
How to mitigate CVE-2017-14107
libzip (Alpine package) - update to 1.2.0-r2
mingw-libzip - addressed in versions 1.1.3-3.fc25, 1.2.0-4.fc26, 1.2.0-4.fc27, 1.3.0-1.fc26, 1.3.0-1.fc27
libzip - addressed in versions 1.3.0-1.fc26, 1.3.0-1.fc27
External References
Related Security Bulletins
- Denial of service in libzip
- Resource exhaustion in libzip (Alpine package)
- Slackware Linux update for libzip
- Fedora 26 update for libzip
- Fedora 27 update for libzip
- Fedora 26 update for mingw-libzip
- Fedora 27 update for mingw-libzip
- Fedora 26 update for mingw-libzip
- Fedora 27 update for mingw-libzip
- Fedora 25 update for mingw-libzip