CVE-2017-5976

Heap-based buffer overflow in the zzip_mem_entry_extra_block function in memdisk.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted ZIP file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gdraheim:zziplib:0.13.56:*:*:*:*:*:*:*
cpe:2.3:a:gdraheim:zziplib:0.13.57:*:*:*:*:*:*:*
cpe:2.3:a:gdraheim:zziplib:0.13.58:*:*:*:*:*:*:*
cpe:2.3:a:gdraheim:zziplib:0.13.59:*:*:*:*:*:*:*
cpe:2.3:a:gdraheim:zziplib:0.13.60:*:*:*:*:*:*:*
cpe:2.3:a:gdraheim:zziplib:0.13.61:*:*:*:*:*:*:*
cpe:2.3:a:gdraheim:zziplib:0.13.62:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

History

10 Jul 2025, 15:44

Type Values Removed Values Added
First Time Gdraheim
Gdraheim zziplib
CPE cpe:2.3:a:zziplib_project:zziplib:0.13.61:*:*:*:*:*:*:*
cpe:2.3:a:zziplib_project:zziplib:0.13.57:*:*:*:*:*:*:*
cpe:2.3:a:zziplib_project:zziplib:0.13.62:*:*:*:*:*:*:*
cpe:2.3:a:zziplib_project:zziplib:0.13.56:*:*:*:*:*:*:*
cpe:2.3:a:zziplib_project:zziplib:0.13.59:*:*:*:*:*:*:*
cpe:2.3:a:zziplib_project:zziplib:0.13.58:*:*:*:*:*:*:*
cpe:2.3:a:zziplib_project:zziplib:0.13.60:*:*:*:*:*:*:*
cpe:2.3:a:gdraheim:zziplib:0.13.56:*:*:*:*:*:*:*
cpe:2.3:a:gdraheim:zziplib:0.13.61:*:*:*:*:*:*:*
cpe:2.3:a:gdraheim:zziplib:0.13.58:*:*:*:*:*:*:*
cpe:2.3:a:gdraheim:zziplib:0.13.60:*:*:*:*:*:*:*
cpe:2.3:a:gdraheim:zziplib:0.13.62:*:*:*:*:*:*:*
cpe:2.3:a:gdraheim:zziplib:0.13.59:*:*:*:*:*:*:*
cpe:2.3:a:gdraheim:zziplib:0.13.57:*:*:*:*:*:*:*

Information

Published : 2017-03-01 15:59

Updated : 2025-07-10 15:44


NVD link : CVE-2017-5976

Mitre link : CVE-2017-5976

CVE.ORG link : CVE-2017-5976


JSON object : View

Products Affected

gdraheim

  • zziplib

debian

  • debian_linux
CWE
CWE-787

Out-of-bounds Write