A use-after-free in the zipdirentread function of zipdirent.c in libzip 1.2.0 allows attackers to have an unspecified impact by attempting to unzip a malformed ZIP archive. NOTE: the discoverer states "This use-after-free is triggered prior to the double free reported in CVE-2017-12858."
[
{
"signature_version": "v1",
"target": {
"file": "lib/zip_dirent.c",
"function": "_zip_dirent_read"
},
"deprecated": false,
"source": "https://github.com/nih-at/libzip/commit/2217022b7d1142738656d891e00b3d2d9179b796",
"id": "CVE-2019-17582-11de36c1",
"digest": {
"function_hash": "247741707400283749085108019441784905923",
"length": 5237.0
},
"signature_type": "Function"
},
{
"signature_version": "v1",
"target": {
"file": "lib/zip_dirent.c"
},
"deprecated": false,
"source": "https://github.com/nih-at/libzip/commit/2217022b7d1142738656d891e00b3d2d9179b796",
"id": "CVE-2019-17582-f2d51449",
"digest": {
"threshold": 0.9,
"line_hashes": [
"126407887668340329650951841643656814806",
"79489290485161336371396243068446216870",
"103867276804264513481566455227706953226",
"200745644596356662579889932048953027052",
"18703439355701899585658934728937768609",
"10360732491339512210894939584152610856"
]
},
"signature_type": "Line"
}
]