Bug #75319 [Fbk->Opn]: Libzip 1.1.2 Security Vulnerability

From: Date: Tue, 17 Oct 2017 16:31:45 +0000
Subject: Bug #75319 [Fbk->Opn]: Libzip 1.1.2 Security Vulnerability
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-211763@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75319&edit=1 ID: 75319 Updated by: cmb@php.net Reported by: scott dot a dot andrews at gmail dot com Summary: Libzip 1.1.2 Security Vulnerability -Status: Feedback +Status: Open Type: Bug Package: Zip Related Operating System: Windows PHP Version: 7.1.10 Block user comment: N Private report: N New Comment: <http://www.cvedetails.com/cve/CVE-2017-12858/> has been fixed as of libzip 1.3.0[1]. [1] <https://nih.at/libzip/NEWS.html> Previous Comments: ------------------------------------------------------------------------ [2017-10-06 07:01:56] ab@php.net Thanks for the report. Please provide a link to the corresponding CVE. Thanks. ------------------------------------------------------------------------ [2017-10-05 13:48:16] scott dot a dot andrews at gmail dot com Description: ------------ The version of Libzip included in 7.1.10 has been identified as a HIGH vulnerability. Libzip: zip_dirent.c Double Free Vulnerability Double free vulnerability in the _zip_dirent_read function in zip_dirent.c in libzip allows attackers to have unspecified impact via unknown vectors. This vulnerability was identified because (1) the detected version of Libzip, 1.1.2, is less than or equal to 1.2.11 In your next release, please upgrade Libzip to at least 1.2.11 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75319&edit=1

« previous php.bugs (#211763) next »