File _patchinfo of Package patchinfo.5571
<patchinfo incident="5571">
<issue id="1056996" tracker="bnc">VUL-0: CVE-2017-14107: libzip: The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0mishandles EOCD records, which allows remote attackers to cause adenial of service (memory allocation failure in _zip_cdir_grow inzip_dirent</issue>
<issue id="2017-14107" tracker="cve" />
<category>security</category>
<rating>moderate</rating>
<packager>pgajdos</packager>
<description>This update for libzip fixes one issues.
This security issue was fixed:
- CVE-2017-14107: The _zip_read_eocd64 function mishandled EOCD records, which
allowed remote attackers to cause a denial of service (memory allocation
failure in _zip_cdir_grow in zip_dirent.c) via a crafted ZIP archive (bsc#1056996).
</description>
<summary>Security update for libzip</summary>
</patchinfo>