CVE-2007-1614
published 2007-03-23CVE-2007-1614: Stack-based buffer overflow in the zzip_open_shared_io function in zzip/file.c in ZZIPlib Library before 0.13.49 allows user-assisted remote attackers to cause…
PriorityP335critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.55%
93.0th percentile
Stack-based buffer overflow in the zzip_open_shared_io function in zzip/file.c in ZZIPlib Library before 0.13.49 allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long filename.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zziplib | < zziplib 0.13.49-0 (bookworm) | zziplib 0.13.49-0 (bookworm) |
| gdraheim | zziplib | >= 0 < 0.13.49-0 | 0.13.49-0 |
| gdraheim | zziplib | >= 0 < 0.13.49-0 | 0.13.49-0 |
| gdraheim | zziplib | >= 0 < 0.13.49-0 | 0.13.49-0 |
| gdraheim | zziplib | >= 0 < 0.13.49-0 | 0.13.49-0 |
| zziplib | zziplib | <= 0.13.45 | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w963-353v-jm7m: Stack-based buffer overflow in the zzip_open_shared_io function in zzip/file
ghsa_unreviewed·2022-05-01
CVE-2007-1614 [HIGH] GHSA-w963-353v-jm7m: Stack-based buffer overflow in the zzip_open_shared_io function in zzip/file
Stack-based buffer overflow in the zzip_open_shared_io function in zzip/file.c in ZZIPlib Library before 0.13.49 allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long filename.
OSV
CVE-2007-1614: Stack-based buffer overflow in the zzip_open_shared_io function in zzip/file
osv·2007-03-23·CVSS 9.3
CVE-2007-1614 [CRITICAL] CVE-2007-1614: Stack-based buffer overflow in the zzip_open_shared_io function in zzip/file
Stack-based buffer overflow in the zzip_open_shared_io function in zzip/file.c in ZZIPlib Library before 0.13.49 allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long filename.
Debian
CVE-2007-1614: zziplib - Stack-based buffer overflow in the zzip_open_shared_io function in zzip/file.c i...
vendor_debian·2007·CVSS 9.3
CVE-2007-1614 [CRITICAL] CVE-2007-1614: zziplib - Stack-based buffer overflow in the zzip_open_shared_io function in zzip/file.c i...
Stack-based buffer overflow in the zzip_open_shared_io function in zzip/file.c in ZZIPlib Library before 0.13.49 allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long filename.
Scope: local
bookworm: resolved (fixed in 0.13.49-0)
bullseye: resolved (fixed in 0.13.49-0)
forky: resolved (fixed in 0.13.49-0)
sid: resolved (fixed in 0.13.49-0)
trixie: resolved (fixed in 0.13.49-0)
No detection rules found.
No public exploits indexed.
http://osvdb.org/33838http://secunia.com/advisories/24586http://secunia.com/advisories/24708http://security.gentoo.org/glsa/glsa-200704-05.xmlhttp://sourceforge.net/project/shownotes.php?group_id=6389&release_id=494587http://www.mandriva.com/security/advisories?name=MDKSA-2007:093http://www.securityfocus.com/bid/23013http://www.securitylab.ru/forum/read.php?FID=21&TID=40858&MID=326187http://www.vupen.com/english/advisories/2007/0998http://osvdb.org/33838http://secunia.com/advisories/24586http://secunia.com/advisories/24708http://security.gentoo.org/glsa/glsa-200704-05.xmlhttp://sourceforge.net/project/shownotes.php?group_id=6389&release_id=494587http://www.mandriva.com/security/advisories?name=MDKSA-2007:093http://www.securityfocus.com/bid/23013http://www.securitylab.ru/forum/read.php?FID=21&TID=40858&MID=326187http://www.vupen.com/english/advisories/2007/0998
2007-03-23
Published