File _patchinfo of Package patchinfo.5571

<patchinfo incident="5571">
  <issue id="1056996" tracker="bnc">VUL-0: CVE-2017-14107: libzip: The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0mishandles EOCD records, which allows remote attackers to cause adenial of service (memory allocation failure in _zip_cdir_grow inzip_dirent</issue>
  <issue id="2017-14107" tracker="cve" />
  <category>security</category>
  <rating>moderate</rating>
  <packager>pgajdos</packager>
  <description>This update for libzip fixes one issues.

This security issue was fixed:

- CVE-2017-14107: The _zip_read_eocd64 function mishandled EOCD records, which
  allowed remote attackers to cause a denial of service (memory allocation
  failure in _zip_cdir_grow in zip_dirent.c) via a crafted ZIP archive (bsc#1056996).
</description>
  <summary>Security update for libzip</summary>
</patchinfo>
openSUSE Build Service is sponsored by