File _patchinfo of Package patchinfo.7295

<patchinfo incident="7295">
  <issue id="1056996" tracker="bnc">VUL-0: CVE-2017-14107: libzip: The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0mishandles EOCD records, which allows remote attackers to cause adenial of service (memory allocation failure in _zip_cdir_grow inzip_dirent</issue>
  <issue id="2017-14107" tracker="cve" />
  <category>security</category>
  <rating>moderate</rating>
  <packager>pgajdos</packager>
  <description>This update for libzip fixes the following security issue:

- CVE-2017-14107: The _zip_read_eocd64 function mishandled EOCD records, which
  allowed remote attackers to cause a denial of service (memory allocation
  failure in _zip_cdir_grow in zip_dirent.c) via a crafted ZIP archive (bsc#1056996).

This update was imported from the SUSE:SLE-12:Update update project.</description>
  <summary>Security update for libzip</summary>
</patchinfo>
openSUSE Build Service is sponsored by