Release date: 2012-03-21
Updated on: 2012-03-22
Affected Systems:
Libzip libzip0.1
Unaffected system:
Libzip 0.10.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52658
Cve id: CVE-2012-1163
Libzip is the library for reading, creating, and modifying zip files.
When libzip is dealing with the size and offset of the central directory structure, the function "_ zip_readcdir ()" has the integer overflow vulnerability, this can cause memory references outside the allocated buffer.
<* Source: vendor
Link: http://secunia.com/advisories/48469/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Libzip
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://nih.at/libzip/index.html