openSUSE Security Update : libzip (openSUSE-2017-1084)
Medium Nessus Plugin ID 103400
SynopsisThe remote openSUSE host is missing a security update.
DescriptionThis update for libzip fixes the following security issue :
- CVE-2017-14107: The _zip_read_eocd64 function mishandled EOCD records, which allowed remote attackers to cause a denial of service (memory allocation failure in
_zip_cdir_grow in zip_dirent.c) via a crafted ZIP archive (bsc#1056996).
This update was imported from the SUSE:SLE-12:Update update project.
SolutionUpdate the affected libzip packages.