Bug #75319 [Fbk->Opn]: Libzip 1.1.2 Security Vulnerability
| From: | cmb@php.net | Date: | Tue, 17 Oct 2017 16:31:45 +0000 |
| Subject: | Bug #75319 [Fbk->Opn]: Libzip 1.1.2 Security Vulnerability | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-211763@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75319&edit=1
ID: 75319
Updated by: cmb@php.net
Reported by: scott dot a dot andrews at gmail dot com
Summary: Libzip 1.1.2 Security Vulnerability
-Status: Feedback
+Status: Open
Type: Bug
Package: Zip Related
Operating System: Windows
PHP Version: 7.1.10
Block user comment: N
Private report: N
New Comment:
<http://www.cvedetails.com/cve/CVE-2017-12858/>
has been fixed as of libzip
1.3.0[1].
[1] <https://nih.at/libzip/NEWS.html>
Previous Comments:
------------------------------------------------------------------------
[2017-10-06 07:01:56] ab@php.net
Thanks for the report. Please provide a link to the corresponding CVE.
Thanks.
------------------------------------------------------------------------
[2017-10-05 13:48:16] scott dot a dot andrews at gmail dot com
Description:
------------
The version of Libzip included in 7.1.10 has been identified as a HIGH vulnerability.
Libzip: zip_dirent.c Double Free Vulnerability
Double free vulnerability in the _zip_dirent_read function in zip_dirent.c in libzip allows
attackers to have unspecified impact via unknown vectors.
This vulnerability was identified because (1) the detected version of Libzip, 1.1.2, is less than or
equal to 1.2.11
In your next release, please upgrade Libzip to at least 1.2.11
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75319&edit=1