Release date: 2012-03-21
Updated on: 2012-03-22
Affected Systems:
Libzip libzip0.1
Unaffected system:
Libzip 0.10.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52658
Cve id: CVE-2012-1162
Libzip is the library for reading, creating, and modifying zip files.
When libzip processes the number of directory items, there is an error in the "_ zip_readcdir ()" function. Through a specially crafted ZIP file, it can cause heap buffer overflow, resulting in arbitrary code execution in the affected application.
<* Source: vendor
Link: http://secunia.com/advisories/48469/
Http://www.nih.at/listarchive/libzip-discuss/msg00252.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Libzip
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://nih.at/libzip/index.html