PatchSiren cyber security CVE debrief
CVE-2017-5975 Gdraheim CVE debrief
CVE-2017-5975 is a heap-based buffer overflow in zziplib’s __zzip_get64 function in fetch.c. According to NVD, affected versions include zziplib 0.13.56 through 0.13.62. The documented impact is denial of service: a crafted ZIP file can cause a crash. NVD maps the weakness to CWE-787 and rates the issue as medium severity.
- Vendor
- Gdraheim
- Product
- Zziplib
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-01
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-01
- Advisory updated
- 2026-05-13
Who should care
Teams that ship, embed, or package zziplib, especially software that opens untrusted ZIP files. Debian users and administrators should also review distro security guidance, since the NVD criteria list Debian 8.0 and 9.0 as affected.
Technical summary
NVD describes a heap-based buffer overflow in __zzip_get64 within fetch.c. The CVSS v3.1 vector is AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, indicating a user-interaction-required issue with high availability impact. The vulnerability is associated with crafted ZIP input and is listed for zziplib versions 0.13.56, 0.13.57, 0.13.58, 0.13.59, 0.13.60, 0.13.61, and 0.13.62.
Defensive priority
Medium. It is a crash/DoS issue rather than a confidentiality or integrity issue, but it affects archive parsing and may be reachable wherever untrusted ZIP content is processed.
Recommended defensive actions
- Identify all products and packages that depend on zziplib and confirm whether they include affected versions 0.13.56 through 0.13.62.
- Apply the vendor or distribution fix referenced by Debian security advisory DSA-3878 or equivalent upstream packaging updates.
- Restrict or sandbox processing of untrusted ZIP files until patched versions are deployed.
- Add monitoring for crashes or abnormal terminations in components that parse ZIP archives.
- If you maintain a downstream package, rebuild against the patched zziplib release provided by your distribution or upstream maintainer.
Evidence notes
The CVE was published on 2017-03-01. Earlier public references in the corpus include a Gentoo technical write-up dated 2017-02-09, an oss-security mailing list post dated 2017-02-14, Debian security advisory DSA-3878, and SecurityFocus BID 96268. NVD’s current record also lists the affected zziplib versions and the CVSS v3.1 vector.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5975 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5975
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5975 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5975
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://blogs.gentoo.org/ago/2017/02/09/zziplib-heap-based-buffer-overflow-in-__zzip_get64-fetch-c/
[email protected] - Exploit, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.