Summary: | <dev-libs/libzip-1.2.0-r1: Double free in _zip_dirent_read function in zip_dirent.c (CVE-2017-12858) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | creffett |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bugzilla.redhat.com/show_bug.cgi?id=1484514 | ||
See Also: | https://bugs.gentoo.org/show_bug.cgi?id=629574 | ||
Whiteboard: | B3 [noglsa cve] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 629574 | ||
Bug Blocks: |
Description
Agostino Sarubbo
![]() 1.2.0-r1 security revbump added in git commit 8ae28c0fa697b98cc15aace97cf1668df29b5fd7 (In reply to Andreas Sturmlechner from comment #1) > 1.2.0-r1 security revbump added in git commit > 8ae28c0fa697b98cc15aace97cf1668df29b5fd7 Thank you, please feel free to call for stabilization when needed or let us know. Gentoo Security Padawan ChrisADR I found another issue in libzip, let's wait a bit to avoid multiple stabilizations. See also bug 629574, cleanup done in git commit b4a9cb3e5493b414c2d671e6e5c1e8bcf084915c. No PoC for ACE/RCE. GLSA Vote: No |