PatchSiren cyber security CVE debrief
CVE-2017-5978 Gdraheim CVE debrief
CVE-2017-5978 is a denial-of-service issue in zziplib 0.13.62. When the library processes a crafted ZIP file, the zzip_mem_entry_new function in memdisk.c can perform an out-of-bounds read and crash. The impact is availability loss rather than data exposure or code execution, and NVD rates the issue as medium severity.
- Vendor
- Gdraheim
- Product
- Zziplib
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-01
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-01
- Advisory updated
- 2026-05-13
Who should care
Organizations that ship or embed zziplib 0.13.62, especially software that opens untrusted ZIP archives. That includes Linux distributions, application packagers, and products that parse ZIP content from users, uploads, or external feeds.
Technical summary
The vulnerability is identified by NVD as CWE-125 (out-of-bounds read). The affected code path is zzip_mem_entry_new in memdisk.c. A crafted ZIP file can drive the parser into reading outside expected bounds, which can terminate the process. The NVD CVSS vector is CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, which indicates user-assisted triggering during file handling and a high availability impact.
Defensive priority
Medium. Treat as a reliability and input-validation issue that can crash ZIP-processing applications. Prioritize remediation if untrusted archives are accepted in production or if the library is widely deployed.
Recommended defensive actions
- Upgrade or replace zziplib 0.13.62 with a vendor-patched or newer release that includes a fix for this issue.
- Apply distribution security updates where available, such as the Debian advisory referenced in the CVE record.
- Restrict exposure by avoiding direct processing of untrusted ZIP files in high-availability services until patched.
- Add regression tests for malformed ZIP inputs and monitor archive-processing services for unexpected crashes.
- Verify which products in your environment embed zziplib and track them as dependent components, not just as direct installations.
Evidence notes
The supplied NVD record states that zzip_mem_entry_new in memdisk.c in zziplib 0.13.62 allows remote attackers to cause a denial of service through a crafted ZIP file. The NVD metadata maps the issue to CWE-125 and lists the vulnerable CPE as cpe:2.3:a:gdraheim:zziplib:0.13.62:*:*:*:*:*:*:*. The record also references Debian DSA-3878, SecurityFocus BID 96268, and a Gentoo blog post describing the out-of-bounds read. No evidence in the supplied corpus indicates known ransomware use or KEV listing.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5978 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5978
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5978 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5978
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://blogs.gentoo.org/ago/2017/02/09/zziplib-out-of-bounds-read-in-zzip_mem_entry_new-memdisk-c/
[email protected] - Exploit, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.