Univention Bugzilla – Bug 54290
libzip: Multiple issues (4.4)
Last modified: 2022-01-05 17:59:00 CET
New Debian libzip 1.1.2-1.1+deb9u1 fixes: This update addresses the following issue: * Memory allocation failure in _zip_cdir_grow function (CVE-2017-14107)
--- mirror/ftp/4.3/unmaintained/4.3-0/source/libzip_1.1.2-1.1.dsc +++ apt/ucs_4.4-0-errata4.4-8/source/libzip_1.1.2-1.1+deb9u1.dsc @@ -1,3 +1,10 @@ +1.1.2-1.1+deb9u1 [Mon, 27 Dec 2021 22:03:02 +0100] Thorsten Alteholz <debian@alteholz.de>: + + * Non-maintainer upload by the LTS Team. + * CVE-2017-14107 + Crafted ZIP archives could allow remote attackers to cause denial of + service due to memorey allocation failure by mishandling EICD records. + 1.1.2-1.1 [Tue, 10 May 2016 12:09:23 +0200] Ondřej Surý <ondrej@debian.org>: [ Hans-Christoph Steiner ] <http://piuparts.knut.univention.de/4.4-8/#907127758317782633>
OK: yaml OK: announce_errata OK: patch OK: piuparts
<https://errata.software-univention.de/#/?erratum=4.4x1137>