Integer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to execute arbitrary code via the size and offset values for the central directory in a zip archive, which triggers "improper restrictions of operations within the bounds of a memory buffer" and an information leak.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2012-07-12T20:00:00Z
Updated: 2024-09-17T00:26:22.595Z
Reserved: 2012-02-14T00:00:00Z
Link: CVE-2012-1163
Vulnrichment
No data.
NVD
Status : Modified
Published: 2012-07-12T20:55:15.000
Modified: 2024-11-21T01:36:34.147
Link: CVE-2012-1163
Redhat