CVE-2012-1162
EPSS 1.7%
Description
Heap-based buffer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a zip archive with the number of directories set to 0, related to an "incorrect loop construct."
How to fix CVE-2012-1162
To remediate CVE-2012-1162, upgrade the affected package to a fixed version below.
- Debian/libzip—upgrade to 0.10.1-1 or later
Is CVE-2012-1162 being exploited?
Low — EPSS is 1.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.10.1-1