The zzip_mem_entry_new function in memdisk.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted ZIP file.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Zziplib | Gdraheim | 0.13.62 (including) | 0.13.62 (including) |
| Zziplib | Ubuntu | esm-infra/xenial | * |
| Zziplib | Ubuntu | precise | * |
| Zziplib | Ubuntu | trusty | * |
| Zziplib | Ubuntu | xenial | * |
| Zziplib | Ubuntu | yakkety | * |
| Zziplib | Ubuntu | zesty | * |