Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0 mishandles EOCD records, which allows remote attackers to cause a denial of service (memory allocation failure in _zip_cdir_grow in zip_dirent.c) via a crafted ZIP archive.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
libzip 安全漏洞
Vulnerability Description
libzip是软件开发者Dieter Baron和Thomas Klausner共同研发的一个用于读取、创建和修改zip压缩包的C库。 libzip 1.3.0之前的版本中的zip_open.c文件的‘_zip_read_eocd64’函数存在安全漏洞。远程攻击者可借助特制的ZIP归档文件利用该漏洞造成拒绝服务(zip_dirent.c文件中的‘_zip_cdir_grow’函数内存分配失败)。
CVSS Information
N/A
Vulnerability Type
N/A