{"affected":[{"ecosystem_specific":{"binaries":[{"libzzip-0-13":"0.13.62-9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12 SP1","name":"zziplib","purl":"pkg:rpm/suse/zziplib&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"0.13.62-9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libzzip-0-13":"0.13.62-9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12 SP2","name":"zziplib","purl":"pkg:rpm/suse/zziplib&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"0.13.62-9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libzzip-0-13":"0.13.62-9.1","zziplib-devel":"0.13.62-9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP1","name":"zziplib","purl":"pkg:rpm/suse/zziplib&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"0.13.62-9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libzzip-0-13":"0.13.62-9.1","zziplib-devel":"0.13.62-9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP2","name":"zziplib","purl":"pkg:rpm/suse/zziplib&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"0.13.62-9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libzzip-0-13":"0.13.62-9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Workstation Extension 12 SP1","name":"zziplib","purl":"pkg:rpm/suse/zziplib&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"0.13.62-9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libzzip-0-13":"0.13.62-9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Workstation Extension 12 SP2","name":"zziplib","purl":"pkg:rpm/suse/zziplib&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"0.13.62-9.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"\nThis update for zziplib fixes the following issues:\n\nSecuirty issues fixed:\n- CVE-2017-5974: heap-based buffer overflow in __zzip_get32 (fetch.c) (bsc#1024517)\n- CVE-2017-5975: heap-based buffer overflow in __zzip_get64 (fetch.c) (bsc#1024528)\n- CVE-2017-5976: heap-based buffer overflow in zzip_mem_entry_extra_block (memdisk.c) (bsc#1024531)\n- CVE-2017-5977: invalid memory read in zzip_mem_entry_extra_block (memdisk.c) (bsc#1024534)\n- CVE-2017-5978: out of bounds read in zzip_mem_entry_new (memdisk.c) (bsc#1024533)\n- CVE-2017-5979: NULL pointer dereference in prescan_entry (fseeko.c) (bsc#1024535)\n- CVE-2017-5980: NULL pointer dereference in zzip_mem_entry_new (memdisk.c) (bsc#1024536)\n- CVE-2017-5981: assertion failure in seeko.c (bsc#1024539)\n- NULL pointer dereference in main (unzzipcat-mem.c) (bsc#1024532)\n- NULL pointer dereference in main (unzzipcat.c) (bsc#1024537)\n","id":"SUSE-SU-2017:1095-1","modified":"2017-04-24T08:30:57Z","published":"2017-04-24T08:30:57Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2017/suse-su-20171095-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1024517"},{"type":"REPORT","url":"https://bugzilla.suse.com/1024528"},{"type":"REPORT","url":"https://bugzilla.suse.com/1024531"},{"type":"REPORT","url":"https://bugzilla.suse.com/1024532"},{"type":"REPORT","url":"https://bugzilla.suse.com/1024533"},{"type":"REPORT","url":"https://bugzilla.suse.com/1024534"},{"type":"REPORT","url":"https://bugzilla.suse.com/1024535"},{"type":"REPORT","url":"https://bugzilla.suse.com/1024536"},{"type":"REPORT","url":"https://bugzilla.suse.com/1024537"},{"type":"REPORT","url":"https://bugzilla.suse.com/1024539"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5974"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5975"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5976"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5977"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5978"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5979"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5980"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5981"}],"related":["CVE-2017-5974","CVE-2017-5975","CVE-2017-5976","CVE-2017-5977","CVE-2017-5978","CVE-2017-5979","CVE-2017-5980","CVE-2017-5981"],"summary":"Security update for zziplib","upstream":["CVE-2017-5974","CVE-2017-5975","CVE-2017-5976","CVE-2017-5977","CVE-2017-5978","CVE-2017-5979","CVE-2017-5980","CVE-2017-5981"]}