Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29321
HistoryFeb 10, 2021 - 3:35 a.m.

Denial Of Service (DoS)

2021-02-1003:35:20
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
vulnerability
use-after-free
zip_dirent.c
application crash
arbitrary code execution
zip archive

EPSS

0.001

Percentile

20.6%

libzip.so is vulnerable to denial of service. A use-after-free exists in the function _zip_dirent_read of zip_dirent.c when an attacker unzips a malformed ZIP archive, resulting in an application crash and potentially allowing for arbitrary code execution.

EPSS

0.001

Percentile

20.6%

Related for VERACODE:29321