[Buildroot] [PATCH] libzip: security bump to version 1.3.0

Peter Korsgaard peter at korsgaard.com
Mon Oct 16 21:51:51 UTC 2017


>>>>> "Peter" == Peter Korsgaard <peter at korsgaard.com> writes:

 > Fixes the following security issues:
 > CVE-2017-12858: Double free vulnerability in the _zip_dirent_read function
 > in zip_dirent.c in libzip allows attackers to have unspecified impact via
 > unknown vectors.

 > CVE-2017-14107: The _zip_read_eocd64 function in zip_open.c in libzip before
 > 1.3.0 mishandles EOCD records, which allows remote attackers to cause a
 > denial of service (memory allocation failure in _zip_cdir_grow in
 > zip_dirent.c) via a crafted ZIP archive.

 > For more details, see
 > https://blogs.gentoo.org/ago/2017/09/01/libzip-use-after-free-in-_zip_buffer_free-zip_buffer-c/
 > https://blogs.gentoo.org/ago/2017/09/01/libzip-memory-allocation-failure-in-_zip_cdir_grow-zip_dirent-c/

 > libzip-1.3.0 also adds optional bzip2 support, so handle that.

 > While we're at it, add a hash for the license file.

 > Signed-off-by: Peter Korsgaard <peter at korsgaard.com>

Committed to 2017.08.x, thanks.

-- 
Bye, Peter Korsgaard


More information about the buildroot mailing list