Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.890994
Kategorie:Debian Local Security Checks
Titel:Debian LTS: Security Advisory for zziplib (DLA-994-1)
Zusammenfassung:CVE-2017-5974;Heap-based buffer overflow in the __zzip_get32 function in fetch.c;in zziplib allows remote attackers to cause a denial of service;(crash) via a crafted ZIP file.;;CVE-2017-5975;Heap-based buffer overflow in the __zzip_get64 function in fetch.c;in zziplib allows remote attackers to cause a denial of service;(crash) via a crafted ZIP file.;;CVE-2017-5976;Heap-based buffer overflow in the zzip_mem_entry_extra_block;function in memdisk.c in zziplib allows remote attackers to cause;a denial of service (crash) via a crafted ZIP file.;;CVE-2017-5978;The zzip_mem_entry_new function in memdisk.c in zziplib allows;remote attackers to cause a denial of service (out-of-bounds;read and crash) via a crafted ZIP file.;;CVE-2017-5979;The prescan_entry function in fseeko.c in zziplib allows remote;attackers to cause a denial of service (NULL pointer dereference;and crash) via a crafted ZIP file.;;CVE-2017-5980;The zzip_mem_entry_new function in memdisk.c in zziplib allows;remote attackers to cause a denial of service (NULL pointer;dereference and crash) via a crafted ZIP file.;;CVE-2017-5981;seeko.c in zziplib allows remote attackers to cause a denial of;service (assertion failure and crash) via a crafted ZIP file.
Beschreibung:Summary:
CVE-2017-5974
Heap-based buffer overflow in the __zzip_get32 function in fetch.c
in zziplib allows remote attackers to cause a denial of service
(crash) via a crafted ZIP file.

CVE-2017-5975
Heap-based buffer overflow in the __zzip_get64 function in fetch.c
in zziplib allows remote attackers to cause a denial of service
(crash) via a crafted ZIP file.

CVE-2017-5976
Heap-based buffer overflow in the zzip_mem_entry_extra_block
function in memdisk.c in zziplib allows remote attackers to cause
a denial of service (crash) via a crafted ZIP file.

CVE-2017-5978
The zzip_mem_entry_new function in memdisk.c in zziplib allows
remote attackers to cause a denial of service (out-of-bounds
read and crash) via a crafted ZIP file.

CVE-2017-5979
The prescan_entry function in fseeko.c in zziplib allows remote
attackers to cause a denial of service (NULL pointer dereference
and crash) via a crafted ZIP file.

CVE-2017-5980
The zzip_mem_entry_new function in memdisk.c in zziplib allows
remote attackers to cause a denial of service (NULL pointer
dereference and crash) via a crafted ZIP file.

CVE-2017-5981
seeko.c in zziplib allows remote attackers to cause a denial of
service (assertion failure and crash) via a crafted ZIP file.

Affected Software/OS:
zziplib on Debian Linux

Solution:
For Debian 7 'Wheezy', these problems have been fixed in version
0.13.56-1.1+deb7u1.

We recommend that you upgrade your zziplib packages.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2017-5974
BugTraq ID: 96268
http://www.securityfocus.com/bid/96268
Debian Security Information: DSA-3878 (Google Search)
http://www.debian.org/security/2017/dsa-3878
https://blogs.gentoo.org/ago/2017/02/09/zziplib-heap-based-buffer-overflow-in-__zzip_get32-fetch-c/
http://www.openwall.com/lists/oss-security/2017/02/14/3
Common Vulnerability Exposure (CVE) ID: CVE-2017-5975
https://blogs.gentoo.org/ago/2017/02/09/zziplib-heap-based-buffer-overflow-in-__zzip_get64-fetch-c/
Common Vulnerability Exposure (CVE) ID: CVE-2017-5976
https://blogs.gentoo.org/ago/2017/02/09/zziplib-heap-based-buffer-overflow-in-zzip_mem_entry_extra_block-memdisk-c/
Common Vulnerability Exposure (CVE) ID: CVE-2017-5978
https://blogs.gentoo.org/ago/2017/02/09/zziplib-out-of-bounds-read-in-zzip_mem_entry_new-memdisk-c/
Common Vulnerability Exposure (CVE) ID: CVE-2017-5979
https://blogs.gentoo.org/ago/2017/02/09/zziplib-null-pointer-dereference-in-prescan_entry-fseeko-c/
Common Vulnerability Exposure (CVE) ID: CVE-2017-5980
https://blogs.gentoo.org/ago/2017/02/09/zziplib-null-pointer-dereference-in-zzip_mem_entry_new-memdisk-c/
Common Vulnerability Exposure (CVE) ID: CVE-2017-5981
https://blogs.gentoo.org/ago/2017/02/09/zziplib-assertion-failure-in-seeko-c/
CopyrightCopyright (C) 2018 Greenbone Networks GmbH http://greenbone.net

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.