Medium severity5.5NVD Advisory· Published Mar 1, 2017· Updated May 13, 2026
CVE-2017-5975
CVE-2017-5975
Description
Heap-based buffer overflow in the __zzip_get64 function in fetch.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted ZIP file.
Affected products
9cpe:2.3:a:gdraheim:zziplib:0.13.56:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:gdraheim:zziplib:0.13.56:*:*:*:*:*:*:*
- cpe:2.3:a:gdraheim:zziplib:0.13.57:*:*:*:*:*:*:*
- cpe:2.3:a:gdraheim:zziplib:0.13.58:*:*:*:*:*:*:*
- cpe:2.3:a:gdraheim:zziplib:0.13.59:*:*:*:*:*:*:*
- cpe:2.3:a:gdraheim:zziplib:0.13.60:*:*:*:*:*:*:*
- cpe:2.3:a:gdraheim:zziplib:0.13.61:*:*:*:*:*:*:*
- cpe:2.3:a:gdraheim:zziplib:0.13.62:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- blogs.gentoo.org/ago/2017/02/09/zziplib-heap-based-buffer-overflow-in-__zzip_get64-fetch-c/nvdExploitThird Party Advisory
- www.debian.org/security/2017/dsa-3878nvdThird Party Advisory
- www.securityfocus.com/bid/96268nvdThird Party AdvisoryVDB Entry
- www.openwall.com/lists/oss-security/2017/02/14/3nvdMailing List
News mentions
0No linked articles in our index yet.